


Perceptive Security
SOC/SIEM Consultancy

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist …
Published:
4 May 2026 at 22:00:00
Alert date:
5 May 2026 at 20:13:49
Source:
nvd.nist.gov
Web Technologies
The MoreConvert Pro plugin for WordPress versions up to 1.9.14 contains an authentication bypass vulnerability. The flaw exists in the guest waitlist verification flow which fails to invalidate or regenerate verification tokens when customer email addresses are changed. This allows unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a verification token for an attacker-controlled email, changing the guest customer email to a target account email through the public waitlist flow, and then using the original verification link to gain unauthorized access.
Technical details
Mitigation steps:
Affected products:
MoreConvert Pro WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5722
https://moreconvert.com/changelog/
https://wordpress.org/plugins/smart-wishlist-for-more-convert/
https://www.wordfence.com/threat-intel/vulnerabilities/id/fe887475-f7e8-4fda-a793-bc6f37b70f3e?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
