CVE-2026-14563

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 07:16

Updated : 2026-09-11 17:35


NVD link : CVE-2026-14563

Mitre link : CVE-2026-14563

CVE.ORG link : CVE-2026-14563


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication