Weak configuration vulnerability in Customer Email Verification for WooCommerce 2.7.4

The Customer Email Verification for WooCommerce plugin for WordPress has a security issue that allows attackers to bypass the email verification process. This can happen if they are able to guess the activation code, which is not random enough. If the plugin is set to automatically log in users after verification and verify accounts for current users, attackers may also be able to bypass authentication for other users.

Detected in:

Customer Email Verification for WooCommerce fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.