The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 07:16
Updated : 2026-09-11 17:35
NVD link : CVE-2026-14563
Mitre link : CVE-2026-14563
CVE.ORG link : CVE-2026-14563
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
