top of page
perceptive_background_267k.jpg

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to th…

Published:

1 mei 2026 om 22:00:00

Alert date:

2 mei 2026 om 06:01:06

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

The User Verification by PickPlugins plugin for WordPress contains an authentication bypass vulnerability affecting all versions up to and including 2.0.46. The vulnerability stems from the use of a loose PHP comparison operator to validate OTP codes in the user_verification_form_wrap_process_otpLogin function. This flaw allows unauthenticated attackers to bypass authentication and log in as any user with a verified email address, including administrators, by simply submitting a 'true' OTP value. The vulnerability poses a critical risk as it enables complete account takeover of privileged users through a trivial exploit.

Technical details

Mitigation steps:

Affected products:

User Verification by PickPlugins WordPress plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page