CVE-2026-14861
User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.
| Vendor | unknown |
| Product | user verification by pickplugins |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown user verification by pickplugins
Be the first to know when new unknown vulnerabilities affecting unknown user verification by pickplugins are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / User Verification by PickPlugins
0 โค 2.0.47
References
Credits
Muni Nitish Kumar Yaddala WPScan