User Verification <= 2.0.47 - Unauthenticated Insecure Direct Object Reference
medium
The User Verification plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.47. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.0.47
- Fix:
- No patched version reported
- Disclosed:
- Aug 17, 2026
CVE-2026-14861 on NVD →
User Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint
critical
The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauth...
- CVSS:
- 9.8
- Affected:
- up to 2.0.46
- Fixed in:
- 2.0.47
- Disclosed:
- May 1, 2026
CVE-2026-7458 on NVD →
User Verification by PickPlugins <= 2.0.45 - Missing Authorization
medium
The User Verification by PickPlugins plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.45. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.0.45
- Fixed in:
- 2.0.46
- Disclosed:
- Mar 23, 2026
CVE-2026-32497 on NVD →
Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.44 - Authentication Bypass to Account Takeover
critical
The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.44. This is due to the plugin not properly validating that an OTP was generated before comparing it t...
- CVSS:
- 9.8
- Affected:
- up to 2.0.44
- Fixed in:
- 2.0.45
- Disclosed:
- Dec 4, 2025
CVE-2025-12374 on NVD →
User Verification <= 1.0.93 - Privilege Escalation
critical
The User Verification plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to obtain login codes for administrators.
- CVSS:
- 9.8
- Affected:
- up to 1.0.93
- Fixed in:
- 1.0.94
- Disclosed:
- Dec 28, 2022
CVE-2022-4693 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database