Executive brief
The Advanced Customized Prompts WordPress plugin fails to validate user permissions before allowing changes to WooCommerce order metadata. An authenticated user with minimal privileges (such as a subscriber) can modify order details belonging to other customers, potentially altering order information, pricing, or custom fields associated with purchases.
Technical details
The plugin contains an Insecure Direct Object Reference (IDOR) vulnerability in WooCommerce order item metadata update functionality. The vulnerability stems from missing capability checks, ownership verification, and nonce validation before processing metadata modifications. Any authenticated user, including those with subscriber-level permissions, can craft requests to update order item metadata for arbitrary orders. The vulnerability allows tampering with custom metadata fields attached to orders, which may include sensitive or business-critical information. No patch has been identified as of the advisory publication date.
Affected products
- Advanced Customized Prompts Advanced Customized Prompts through 1.0.1
Timeline
- 2026-09-09: disclosed
- 2026-09-11: advisory