The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 CWE-79 |
Fri, 11 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product. | |
| Title | Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configuration | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-11T06:00:07.079Z
Reserved: 2026-07-03T10:04:39.840Z
Link: CVE-2026-14565
No data.
Status : Received
Published: 2026-09-11T07:16:46.277
Modified: 2026-09-11T07:16:46.277
Link: CVE-2026-14565
No data.
OpenCVE Enrichment
Updated: 2026-09-11T07:30:10Z