PT-2026-71391 · WordPress · Customer Email Verification For Woocommerce

CVE-2026-14182

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Customer Email Verification for WooCommerce versions prior to 3.2.6
Description An issue exists where the plugin fails to correctly validate the email-verification activation code. This occurs due to a loose comparison, which enables a type-juggling authentication bypass. An unauthenticated attacker can use a crafted value type to satisfy the validation process, allowing them to verify and take over the account of any registered user who has not yet confirmed their email address.
Recommendations Update Customer Email Verification for WooCommerce to version 3.2.6 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14182

Affected Products

Customer Email Verification For Woocommerce