CVE-2026-14861
Received Received - Intake

Unauthenticated Email Verification Bypass in User Verification by PickPlugins

Vulnerability report for CVE-2026-14861, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: WPScan

Description

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pickplugins user_verification to 2.0.47 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the User Verification WordPress plugin versions 2.0.47 or earlier. It allows unauthenticated attackers to lock out any user, including administrators, by resetting their email-verification status. The issue occurs because the plugin does not verify if a request to resend a verification email is authorized for the specified user or bind the protecting token to that user.

Detection Guidance

Check if the User Verification by PickPlugins plugin version 2.0.47 or earlier is installed on your WordPress site. Look for unauthorized resend verification email requests in server logs or WordPress activity logs.

Impact Analysis

If you use the affected WordPress plugin, an attacker could exploit this flaw to lock you or other users out of your accounts by resetting email-verification statuses. This could prevent legitimate access to your WordPress site, including administrative functions, leading to potential loss of control over your website.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized access to user accounts, potentially leading to data breaches or unauthorized modifications. GDPR requires protecting user data and ensuring access controls, while HIPAA mandates safeguarding protected health information. Exploitation of this flaw could violate these requirements.

Mitigation Strategies

Immediately update the User Verification plugin to the latest version if available. If no update exists, consider disabling the plugin temporarily until a patch is released. Review user accounts for unauthorized changes and revoke any suspicious sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14861. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart