Authentication vulnerability in Email Verification for WooCommerce 1.8.1

The Email Verification for WooCommerce plugin for WordPress has a security vulnerability that can be exploited to bypass the authentication process. This vulnerability allows malicious users to log in as site administrators without providing any valid credentials. The vulnerability is due to an insufficient validation of the alg_wc_ev_activation_code value found in the verify() function. The vulnerability affects all versions of the plugin up to version 1.8.1.

Detected in:

Customer Email Verification for WooCommerce fixed vulnerable versions:
Email Verification for WooCommerce Pro fixed vulnerable versions: >= * <= 1.8.1
Email Verification for WooCommerce open vulnerable versions: >= * <= 1.8.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.