plugin

Emails Verification For Woocommerce Vulnerabilities

13 known security issues reported for the Emails Verification For Woocommerce WordPress plugin. Most recent disclosed Aug 11, 2026.

1 critical 4 high 1 medium

Running Emails Verification For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Privilege Escalation

critical

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.2.6 (exclusive). This is due to a loose comparison that bypasses an email verification code check. This makes it possible for unauthenticated attackers to elevate their privileges by taking...

CVSS:
9.8
Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Aug 11, 2026

CVE-2026-14182 on NVD →

Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 2.9.5

unknown

[en] The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including emails as...

Affected:
up to 2.9.5
Fixed in:
2.9.5
Disclosed:
Feb 15, 2025

CVE-2024-13525 on NVD →

Customer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including emails as well...

CVSS:
6.5
Affected:
up to 2.9.4
Fixed in:
2.9.5
Disclosed:
Feb 14, 2025

CVE-2024-13525 on NVD →

Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 2.9.6

unknown

[en] The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, wi...

Affected:
up to 2.9.6
Fixed in:
2.9.6
Disclosed:
Feb 12, 2025

CVE-2024-13528 on NVD →

Customer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcode

high

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, with Co...

CVSS:
7.5
Affected:
up to 2.9.5
Fixed in:
2.9.6
Disclosed:
Feb 11, 2025

CVE-2024-13528 on NVD →

Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 2.9.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Verification for WooCommerce allows SQL Injection.This issue affects Email Verification for WooCommerce: from n/a through 2.8.10.

Affected:
up to 2.9.0
Fixed in:
2.9.0
Disclosed:
Oct 17, 2024

CVE-2024-49305 on NVD →

Email Verification for WooCommerce <= 2.8.10 - Unauthenticated SQL Injection

high

The Email Verification for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append ad...

CVSS:
7.5
Affected:
up to 2.8.10
Fixed in:
2.9.0
Disclosed:
Oct 15, 2024

CVE-2024-49305 on NVD →

Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 2.7.5

unknown

[en] The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification,...

Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Apr 30, 2024

CVE-2024-4185 on NVD →

Customer Email Verification for WooCommerce <= 2.7.4 - Email Verification and Authentication Bypass due to Insufficient Randomness

high

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and...

CVSS:
8.1
Affected:
up to 2.7.4
Fixed in:
2.7.5
Disclosed:
Apr 29, 2024

CVE-2024-4185 on NVD →

Email Verification for WooCommerce <= 1.8.1 - Authentication Bypass

high

The Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass due to insufficient validation on the alg_wc_ev_activation_code value found in the verify() function which makes it possible for users to spoof email validation for any user, including administrators, that will auto-log t...

CVSS:
8.8
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Jul 14, 2020

Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 1.8.2

unknown

Bypass vulnerability discovered by WordPress Email Verification for WooCommerce plugin (versions <= 1.8.1).

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Jul 14, 2020

Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 1.8.2

unknown

The Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass due to insufficient validation on the alg_wc_ev_activation_code value found in the verify() function which makes it possible for users to spoof email validation for any user, including administrators, that will auto-log t...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Jul 14, 2020

Customer Email Verification for WooCommerce [emails-verification-for-woocommerce] < 1.8.2

unknown

The plugin is affected by a loose comparison issue, which could allow any user to log in as administrator.

Affected:
up to 1.8.2
Fixed in:
1.8.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database