AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14182

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Customer Email Verification for WooCommerce plugin for WordPress prior to version 3.2.6 is vulnerable due to improper validation of email-verification activation codes, enabling attackers to exploit this weakness and verify accounts of registered users who have not confirmed their email addresses. This could lead to unauthorized account takeovers, posing a significant risk to user data and site integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-14182
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%
WordPress

Original NVD Description

The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.