SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14566

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The advanced-customized-prompts WordPress plugin versions up to 1.0.1 are vulnerable due to inadequate checks on capability, ownership, and nonce validation when updating WooCommerce order item metadata. This flaw allows any authenticated user, including those with low-level permissions like subscribers, to manipulate custom metadata for orders belonging to other customers, potentially leading to data integrity issues. WordPress site administrators and developers using this plugin should prioritize patching or mitigating this vulnerability to protect customer data.

CVE
CVE-2026-14566
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
WordPress

Original NVD Description

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers.