Authentication vulnerability in Customer Email Verification for WooCommerce 2.9.5

A plugin called Customer Email Verification for WooCommerce on WordPress has a security issue that allows unauthorized access. This is because the plugin has a feature that creates a link to confirm an email, but it uses a placeholder email instead. This means that anyone with Contributor-level access or higher can use this link to log into any unverified user’s account. To make use of this vulnerability, the ‘Fine tune placement’ option in the plugin settings must be turned on.

Detected in:

Customer Email Verification for WooCommerce fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.