๐Ÿ” CVE Alert

CVE-2026-14182

UNKNOWN 0.0

Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.

Vendor unknown
Product customer email verification for woocommerce
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for unknown customer email verification for woocommerce

Be the first to know when new unknown vulnerabilities affecting unknown customer email verification for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Customer Email Verification for WooCommerce
2.4.0 < 3.2.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/ef4e95a3-6f90-4423-9551-9ac28f7b6291/

Credits

Revanth Hari Narayana Matte WPScan