Email Verification for WooCommerce <= 1.8.1 - Authentication Bypass
highThe Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass due to insufficient validation on the alg_wc_ev_activation_code value found in the verify() function which makes it possible for users to spoof email validation for any user, including administrators, that will auto-log t...
- CVSS:
- 8.8
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Jul 14, 2020