CVE-2026-14861
User Verification by PickPlugins
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.
- CVSS
- 7.5
- EPSS
- 0.31% 23.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.19