๐Ÿ” CVE Alert

CVE-2026-14861

UNKNOWN 0.0

User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.

Vendor unknown
Product user verification by pickplugins
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown user verification by pickplugins

Be the first to know when new unknown vulnerabilities affecting unknown user verification by pickplugins are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / User Verification by PickPlugins
0 โ‰ค 2.0.47

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4dff3634-4b4f-48e2-a8c9-dda7e2b682fd/

Credits

Muni Nitish Kumar Yaddala WPScan