PT-2026-78281 · Pickplugins · User Verification

CVE-2026-14861

·

Published

2026-08-19

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions User Verification by PickPlugins WordPress plugin versions prior to 2.0.48
Description The plugin fails to verify if a request to resend a verification email is authorized for the specified user and does not bind the protection token to that user. This allows unauthenticated attackers to reset the email-verification status of arbitrary users, which can result in users, including administrators, being locked out of their accounts.
Recommendations Update the User Verification by PickPlugins WordPress plugin to version 2.0.48 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14861

Affected Products

User Verification