Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-32497
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32497 is a Weak Authentication vulnerability in the PickPlugins User Verification WordPress plugin that allows unauthenticated attackers to abuse the authentication mechanism, specifically enabling email verification bypass. It affects all versions of the plugin from n/a through 2.0.45. The vulnerability was published on March 25, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).

Technical details

The vulnerability is classified as a Weak Authentication flaw (Authentication Abuse) in the User Verification plugin's email verification workflow. An unauthenticated remote attacker can exploit this issue over the network with low attack complexity and no user interaction required, suggesting the plugin fails to properly validate or enforce email verification tokens or steps before granting access. This allows attackers to bypass the email verification gate that is intended to confirm user identity during registration or login flows. No specific CWE identifier has been assigned, but the behavior aligns with CWE-287 (Improper Authentication) (Feedly, Patchstack).

Impact

Successful exploitation allows an attacker to bypass the email verification requirement enforced by the plugin, potentially enabling unauthorized account creation or access to WordPress sites that rely on the plugin for user validation. The integrity impact is rated low, with no direct confidentiality or availability impact, meaning attackers can manipulate the verification state of accounts without necessarily gaining full system access. However, on sites where email verification is the primary access control gate, this bypass could allow fraudulent accounts to be activated and used for spam, privilege escalation attempts, or other malicious activity (Feedly).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.022% (0.000220), indicating a currently low probability of active exploitation in the wild. No evidence of in-the-wild exploitation, threat actor attribution, or CISA KEV catalog inclusion has been reported as of the available data. No public proof-of-concept exploit code has been identified (Feedly, Patchstack).

Mitigation and workarounds

Users of the PickPlugins User Verification WordPress plugin should update to a version beyond 2.0.45 as soon as a patched release is made available by the vendor. In the interim, site administrators should consider disabling the plugin if email verification is not strictly required, or implement additional access controls (such as manual user approval) to compensate for the bypass risk. Monitoring WordPress user registration logs for unexpected account activations without corresponding email verification events is also recommended (Patchstack, Feedly).

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report covering March 23–29, 2026, highlighting it as part of a broader set of plugin security issues disclosed that week (Wordfence Blog). No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability aggregator coverage.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88788MEDIUM6.8
  • text-styler
NoNoSep 19, 2026
CVE-2026-9858MEDIUM4.3
  • wc-partial-shipment
NoYesSep 19, 2026
CVE-2026-9766MEDIUM4.3
  • empik-for-woocommerce
NoYesSep 19, 2026
CVE-2026-9613MEDIUM4.3
  • datalogics
NoYesSep 19, 2026
CVE-2026-87848LOW3.7
  • mpcx-lightbox
NoNoSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management