top of page
perceptive_background_267k.jpg

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist …

Published:

4 mei 2026 om 22:00:00

Alert date:

5 mei 2026 om 20:13:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

The MoreConvert Pro plugin for WordPress versions up to 1.9.14 contains an authentication bypass vulnerability. The flaw exists in the guest waitlist verification flow which fails to invalidate or regenerate verification tokens when customer email addresses are changed. This allows unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a verification token for an attacker-controlled email, changing the guest customer email to a target account email through the public waitlist flow, and then using the original verification link to gain unauthorized access.

Technical details

Mitigation steps:

Affected products:

MoreConvert Pro WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page