SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14861

HIGH · CVSS 7.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The User Verification by PickPlugins WordPress plugin prior to version 2.0.47 is vulnerable due to inadequate authorization checks for resending verification emails, enabling unauthenticated attackers to manipulate user email-verification statuses. This flaw can lead to unauthorized account access and potentially lock out users, including administrators, from their accounts. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of account compromise.

CVE
CVE-2026-14861
Severity
HIGH
CVSS
7.5
EPSS
0.31%
WordPress

Original NVD Description

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.