Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Privilege Escalation
critical
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.2.6 (exclusive). This is due to a loose comparison that bypasses an email verification code check. This makes it possible for unauthenticated attackers to elevate their privileges by taking...
- CVSS:
- 9.8
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.6
- Disclosed:
- Aug 11, 2026
CVE-2026-14182 on NVD →
Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 2.9.5
unknown
[en] The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including emails as...
- Affected:
- up to 2.9.5
- Fixed in:
- 2.9.5
- Disclosed:
- Feb 15, 2025
CVE-2024-13525 on NVD →
Customer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including emails as well...
- CVSS:
- 6.5
- Affected:
- up to 2.9.4
- Fixed in:
- 2.9.5
- Disclosed:
- Feb 14, 2025
CVE-2024-13525 on NVD →
Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 2.9.6
unknown
[en] The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, wi...
- Affected:
- up to 2.9.6
- Fixed in:
- 2.9.6
- Disclosed:
- Feb 12, 2025
CVE-2024-13528 on NVD →
Customer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcode
high
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, with Co...
- CVSS:
- 7.5
- Affected:
- up to 2.9.5
- Fixed in:
- 2.9.6
- Disclosed:
- Feb 11, 2025
CVE-2024-13528 on NVD →
Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 2.9.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Verification for WooCommerce allows SQL Injection.This issue affects Email Verification for WooCommerce: from n/a through 2.8.10.
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Oct 17, 2024
CVE-2024-49305 on NVD →
Email Verification for WooCommerce <= 2.8.10 - Unauthenticated SQL Injection
high
The Email Verification for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append ad...
- CVSS:
- 7.5
- Affected:
- up to 2.8.10
- Fixed in:
- 2.9.0
- Disclosed:
- Oct 15, 2024
CVE-2024-49305 on NVD →
Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 2.7.5
unknown
[en] The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification,...
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.5
- Disclosed:
- Apr 30, 2024
CVE-2024-4185 on NVD →
Customer Email Verification for WooCommerce <= 2.7.4 - Email Verification and Authentication Bypass due to Insufficient Randomness
high
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and...
- CVSS:
- 8.1
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.5
- Disclosed:
- Apr 29, 2024
CVE-2024-4185 on NVD →
Email Verification for WooCommerce <= 1.8.1 - Authentication Bypass
high
The Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass due to insufficient validation on the alg_wc_ev_activation_code value found in the verify() function which makes it possible for users to spoof email validation for any user, including administrators, that will auto-log t...
- CVSS:
- 8.8
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Jul 14, 2020
Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 1.8.2
unknown
Bypass vulnerability discovered by WordPress Email Verification for WooCommerce plugin (versions <= 1.8.1).
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jul 14, 2020
Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 1.8.2
unknown
The Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass due to insufficient validation on the alg_wc_ev_activation_code value found in the verify() function which makes it possible for users to spoof email validation for any user, including administrators, that will auto-log t...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jul 14, 2020
Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 1.8.2
unknown
The plugin is affected by a loose comparison issue, which could allow any user to log in as administrator.
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database