plugin

User Verification Vulnerabilities

5 known security issues reported for the User Verification WordPress plugin. Most recent disclosed Aug 17, 2026.

3 critical 2 medium

Running User Verification on your site? Check whether your installed version is affected.

Scan your site free

User Verification <= 2.0.47 - Unauthenticated Insecure Direct Object Reference

medium

The User Verification plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.47. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.0.47
Fix:
No patched version reported
Disclosed:
Aug 17, 2026

CVE-2026-14861 on NVD →

User Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint

critical

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauth...

CVSS:
9.8
Affected:
up to 2.0.46
Fixed in:
2.0.47
Disclosed:
May 1, 2026

CVE-2026-7458 on NVD →

User Verification by PickPlugins <= 2.0.45 - Missing Authorization

medium

The User Verification by PickPlugins plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.45. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.0.45
Fixed in:
2.0.46
Disclosed:
Mar 23, 2026

CVE-2026-32497 on NVD →

Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.44 - Authentication Bypass to Account Takeover

critical

The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.44. This is due to the plugin not properly validating that an OTP was generated before comparing it t...

CVSS:
9.8
Affected:
up to 2.0.44
Fixed in:
2.0.45
Disclosed:
Dec 4, 2025

CVE-2025-12374 on NVD →

User Verification <= 1.0.93 - Privilege Escalation

critical

The User Verification plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to obtain login codes for administrators.

CVSS:
9.8
Affected:
up to 1.0.93
Fixed in:
1.0.94
Disclosed:
Dec 28, 2022

CVE-2022-4693 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database