PT-2026-71391 · WordPress · Customer Email Verification For Woocommerce
CVE-2026-14182
·
Published
2026-08-13
·
Updated
2026-08-13
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Customer Email Verification for WooCommerce versions prior to 3.2.6
Description
An issue exists where the plugin fails to correctly validate the email-verification activation code. This occurs due to a loose comparison, which enables a type-juggling authentication bypass. An unauthenticated attacker can use a crafted value type to satisfy the validation process, allowing them to verify and take over the account of any registered user who has not yet confirmed their email address.
Recommendations
Update Customer Email Verification for WooCommerce to version 3.2.6 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Customer Email Verification For Woocommerce