Executive brief
The Advanced Customized Prompts WordPress plugin allows low-privileged users (including subscribers) to inject malicious JavaScript into popup configurations without any permission or validation checks. When visitors view an affected product, the injected script executes in their browsers, potentially stealing credentials, redirecting to malicious sites, or defacing content. Site administrators relying on role-based access controls are exposed to compromise by untrusted users.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the Advanced Customized Prompts plugin (CVE-2026-14565, CWE-79). The plugin fails to validate user capabilities, ownership, or nonce tokens before saving popup configuration data to product metadata, and does not escape output when rendering stored values. Any authenticated user—including subscribers with minimal privileges—can craft malicious JavaScript payloads and store them via the popup configuration endpoint. When product pages are viewed by other users or site visitors, the unescaped payload executes in their browser context. No patch is currently available as of the advisory date.
Affected products
- Advanced Customized Prompts Advanced Customized Prompts through 1.0.1
Timeline
- 2026-09-09: disclosed
- 2026-09-11: advisory