Impact
The WordPress plugin Advanced Customized Prompts mishandles authentication by issuing an authenticated session for any email address after a password check is skipped during an unauthenticated action. This flaw allows an attacker to log in as any registered user, including administrators, or to create arbitrary new accounts. The vulnerability is an authentication bypass that can result in full account takeover, jeopardizing confidentiality, integrity, and availability of the site.
Affected Systems
Users who have installed Advanced Customized Prompts on any WordPress site are affected, regardless of the WordPress core version. The flaw exists in all plugin releases up to and including version 1.0.1. No vendor-delivered patch is currently listed.
Risk and Exploitability
The CVSS score is not provided, so formal severity quantification is unavailable. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is an unauthenticated request to the plugin’s endpoint, requiring no pre‑existing credentials. Because the flaw permits immediate session acquisition, an attacker could immediately access administrative functions or create malicious accounts, making the exposure period particularly risky.
OpenCVE Enrichment