CVE 9.8 CRITICAL

Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.39 - Authentication Bypass to Account Takeover_CVE-2025-12374

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.39. This is due to the plugin not properly validating that an OTP was generated before comparing it to user input in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting an empty OTP value.

AI Analysis

Authentication bypass vulnerability in User Verification plugin for WordPress, allowing unauthenticated attackers to log in as any user with a verified email address.

Basic Information

ID CVE-2025-12374
Source Wordfence
Published Dec 5, 2025 at 06:07

Affected Product

Vendor pickplugins
Product User Verification by PickPlugins
Version *
Affected Versions pickplugins User Verification by PickPlugins *

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor PickPlugins
Product User Verification
Version 2.0.39 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.