CVE-2026-14861

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-14861

Mitre link : CVE-2026-14861

CVE.ORG link : CVE-2026-14861


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key