SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14565

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The advanced-customized-prompts WordPress plugin versions up to 1.0.1 is vulnerable due to inadequate checks on user capabilities and lack of proper output escaping, enabling authenticated users to inject malicious JavaScript into product popups. This could lead to cross-site scripting (XSS) attacks, compromising the security of visitors' browsers. WordPress site administrators and developers using this plugin should prioritize remediation to mitigate potential exploitation.

CVE
CVE-2026-14565
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%
WordPress Java

Original NVD Description

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store JavaScript that executes in the browser of visitors viewing the affected product.