CRITICAL
9.8 CVE-2026-14563 Published 11 Sept 2026
WordPress Plugin Advanced Customized Prompts Unauthenticated Login Vulnerability
Worried this affects one of your servers?
The advanced-customized-prompts WordPress plugin, up to version 1.0.1, has a security flaw.
This plugin does not verify passwords before issuing authenticated sessions for supplied email addresses in unauthenticated actions.
This allows unauthenticated attackers to log in as any registered user, including administrators, or create new accounts.
Reference: CVE-2026-14563 on NVD
← Back to Security News