PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14566 advanced-customized-prompts CVE debrief

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers. This vulnerability poses a risk to data integrity and could lead to potential security issues if exploited. Defenders should assess the exposure of their WordPress installations using this plugin and verify the presence of updated versions.

Vendor
advanced-customized-prompts
Product
advanced-customized-prompts
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders responsible for WordPress installations using the advanced-customized-prompts plugin should assess exposure and verify the presence of updated versions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure that their systems are protected against potential data integrity issues.

Why it matters

The CVE-2026-14566 vulnerability in the advanced-customized-prompts WordPress plugin allows any authenticated user to update WooCommerce order item metadata without proper checks, posing a risk to data integrity.

  • Tampering with custom metadata of orders belonging to other customers
  • Potential data integrity issues

Technical summary

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order. This allows any authenticated user, such as a subscriber, to tamper with the custom metadata of orders belonging to other customers. The vulnerability is caused by a lack of proper checks in the plugin's code, which could lead to data integrity issues if exploited. Defenders should prioritize verifying the presence of this plugin in their WordPress installations and ensure that it is updated to a version that includes the necessary checks.

Defensive priority

Defenders should prioritize verifying the presence of this plugin in their WordPress installations and ensure that it is updated to a version that includes the necessary checks.

Recommended defensive actions

  • Verify the presence of the advanced-customized-prompts WordPress plugin in your installation
  • Check if the plugin is updated to a version that includes the necessary checks
  • Restrict access to sensitive metadata updates
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, including its description and CVSS score. The vulnerability was disclosed on 2026-09-11T07:16:46.373Z. The CVE Program and NVD entries provide source-provided CVE metadata and official vulnerability assessment. However, the exact scope of affected systems and potential impact on data integrity are not explicitly stated, requiring defenders to verify the presence of updated versions and assess exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14566 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14566

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14566 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14566

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.