VYPR

User Verification by PickPlugins

by WordPress

CVEs (2)

  • CVE-2026-7458CriMay 2, 2026
    risk 0.57cvss 9.8epss 0.01

    The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin"…

  • CVE-2026-14861HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users'…