WordPress Plugin Vulnerabilities

Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover

Description

The plugin does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
0xBassia
Submitter
0xBassia
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-09 (about 2 days ago)
Added
2026-09-09 (about 1 day ago)
Last Updated
2026-09-10 (about 8 hours ago)

Other