WordPress Plugin Vulnerabilities

User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR

Description

The plugin does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Muni Nitish Kumar Yaddala
Submitter
Muni Nitish Kumar Yaddala
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-18 (about 1 day ago)

Other