CyberRota Analysis
AI-GeneratedThe User Verification by PickPlugins WordPress plugin prior to version 2.0.47 is vulnerable due to inadequate authorization checks for resending verification emails, enabling unauthenticated attackers to manipulate user email-verification statuses. This flaw can lead to unauthorized account access and potentially lock out users, including administrators, from their accounts. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of account compromise.
Original NVD Description
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.