Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High1
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-08-19

CVE-2026-14861 - User Verification By Pickplugins

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.

PLUGIN User Verification By Pickplugins

CVE-2026-14861

HIGH CVSS 7.5 2026-08-19
Threat Entry Updated 2026-06-17

CVE-2026-7458 - User Verification By Pickplugins

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value.

PLUGIN User Verification By Pickplugins

CVE-2026-7458

CRITICAL CVSS 9.8 2026-05-02
Scroll to top