VYPR

User Email Verification For Woocommerce

by WordPress

CVEs (3)

  • CVE-2023-2781HigJun 3, 2023
    risk 0.53cvss 8.1epss 0.01

    The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This…

  • CVE-2023-39162HigSep 4, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.

  • CVE-2024-13528HigFeb 12, 2025
    risk 0.42cvss 7.5epss 0.00

    The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it…

VYPR — Vulnerability Intelligence