Description
The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product.
Published: 2026-09-11
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑site Scripting
Action: Update plugin
AI Analysis

Impact

The Advanced Customized Prompts WordPress plugin through version 1.0.1 allows any authenticated user such as a subscriber to inject JavaScript into the product popup configuration without performing a capability check or escaping the stored visitors, the injected script executes in the visitor’s browser, enabling attackers to steal session cookies, deface the site, or perform other malicious actions against customers. This vulnerability is a classic stored cross‑site scripting flaw.

Affected Systems

WordPress installations that have the Advanced Customized Prompts plugin of version 1.0.1 or earlier installed are affected. The issue occurs when an authorized subscriber creates or edits a product popup configuration using that plugin.

Risk and Exploitability

The EPSS score is 0.00158, indicating a low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but the high impact of stored XSS indicates that exploitation is feasible once an authenticated user has access to the plugin’s configuration interface. An attacker who can log into the site as a subscriber can store malicious JavaScript that is then executed automatically for any visitor viewing the product, making the attack vector an authenticated exploitation of the WordPress back‑end followed by. The CVSS score of 5.4 indicates moderate severity due to the potential for widespread browser compromise.

Generated by OpenCVE AI on September 11, 2026 at 15:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Advanced Customized Prompts plugin to any version newer than 1.0.1 after verifying the vendor’s release notes include the fix.
  • Add a server‑side capability check or restrict the popup configuration edit capability to administrators only, preventing subscribers from modifying settings.
  • Sanitize or escape any content stored by the plugin before saving it and ensure that all stored configuration values are properly escaped, review all product pages for unexpected JavaScript and remove any that appears without source control confirmation.

Generated by OpenCVE AI on September 11, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-79

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product.
Title Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configuration
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:10:18.544Z

Reserved: 2026-07-03T10:04:39.840Z

Link: CVE-2026-14565

cve-icon Vulnrichment

Updated: 2026-09-11T10:02:37.546Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:46.277

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-14565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T15:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')