VYPR

Advanced Customized Prompts

by WordPress

CVEs (3)

  • CVE-2026-14566Sep 11, 2026
    risk 0.00cvss epss

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata…

  • CVE-2026-14565Sep 11, 2026
    risk 0.00cvss epss

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store…

  • CVE-2026-14563Sep 11, 2026
    risk 0.00cvss epss

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including…