The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers.
History

Fri, 11 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-862

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-862

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata of orders belonging to other customers.
Title Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata Tampering
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-09-11T06:00:07.254Z

Updated: 2026-09-11T10:10:04.131Z

Reserved: 2026-07-03T10:05:36.124Z

Link: CVE-2026-14566

cve-icon Vulnrichment

Updated: 2026-09-11T10:02:28.146Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:46.373

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-14566

cve-icon Redhat

No data.