CVE-2026-5722

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a valid guest verification token for an attacker-controlled email, changing the same guest customer email to the target account email through the public waitlist flow, and then using the original verification link.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-05 02:16

Updated : 2026-06-17 10:59


NVD link : CVE-2026-5722

Mitre link : CVE-2026-5722

CVE.ORG link : CVE-2026-5722


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication