Unrated severityNVD Advisory· Published Sep 11, 2026
CVE-2026-14565
CVE-2026-14565
Description
The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.0.1+ 1 more
- (no CPE)range: <=1.0.1
- (no CPE)range: <=1.0.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.