Description
The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the -user_verification_form_wrap_process_otpLogin- function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a -true- OTP value.
CVSS 9.8EPSS 0.5780000000000001%Risque 1.03
Voir la source- Publication
- 2026-05-02 05:16:01
- Versions concernées
- <=2.0.46
- Type
- Installed app
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H