CVE 9.8 CRITICAL

User Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint_CVE-2026-7458

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value.

AI Analysis

Authentication bypass vulnerability in User Verification by PickPlugins plugin for WordPress, allowing unauthenticated attackers to log in as any user with a verified email address.

Basic Information

ID CVE-2026-7458
Source Wordfence
Published May 2, 2026 at 04:27

Affected Product

Vendor pickplugins
Product User Verification by PickPlugins
Affected Versions pickplugins User Verification by PickPlugins 0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor PickPlugins
Product User Verification by PickPlugins
Version 2.0.46 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.