CVE-2026-14563 UNKNOWN

CVE-2026-14563

Published: 2026-09-11

Description

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…