PatchSiren cyber security CVE debrief
CVE-2026-14566 advanced-customized-prompts CVE debrief
The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers. This vulnerability poses a risk to data integrity and could lead to potential security issues if exploited. Defenders should assess the exposure of their WordPress installations using this plugin and verify the presence of updated versions.
- Vendor
- advanced-customized-prompts
- Product
- advanced-customized-prompts
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-11
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-11
- Advisory updated
- 2026-09-11
Who should care
Defenders responsible for WordPress installations using the advanced-customized-prompts plugin should assess exposure and verify the presence of updated versions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure that their systems are protected against potential data integrity issues.
Why it matters
The CVE-2026-14566 vulnerability in the advanced-customized-prompts WordPress plugin allows any authenticated user to update WooCommerce order item metadata without proper checks, posing a risk to data integrity.
- Tampering with custom metadata of orders belonging to other customers
- Potential data integrity issues
Technical summary
The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order. This allows any authenticated user, such as a subscriber, to tamper with the custom metadata of orders belonging to other customers. The vulnerability is caused by a lack of proper checks in the plugin's code, which could lead to data integrity issues if exploited. Defenders should prioritize verifying the presence of this plugin in their WordPress installations and ensure that it is updated to a version that includes the necessary checks.
Defensive priority
Defenders should prioritize verifying the presence of this plugin in their WordPress installations and ensure that it is updated to a version that includes the necessary checks.
Recommended defensive actions
- Verify the presence of the advanced-customized-prompts WordPress plugin in your installation
- Check if the plugin is updated to a version that includes the necessary checks
- Restrict access to sensitive metadata updates
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, including its description and CVSS score. The vulnerability was disclosed on 2026-09-11T07:16:46.373Z. The CVE Program and NVD entries provide source-provided CVE metadata and official vulnerability assessment. However, the exact scope of affected systems and potential impact on data integrity are not explicitly stated, requiring defenders to verify the presence of updated versions and assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14566 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14566
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14566 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14566
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/01094477-a9ad-41d9-9acd-f6ed37e6e605/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.