
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32497 is a Weak Authentication vulnerability in the PickPlugins User Verification WordPress plugin that allows unauthenticated attackers to abuse the authentication mechanism, specifically enabling email verification bypass. It affects all versions of the plugin from n/a through 2.0.45. The vulnerability was published on March 25, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).
The vulnerability is classified as a Weak Authentication flaw (Authentication Abuse) in the User Verification plugin's email verification workflow. An unauthenticated remote attacker can exploit this issue over the network with low attack complexity and no user interaction required, suggesting the plugin fails to properly validate or enforce email verification tokens or steps before granting access. This allows attackers to bypass the email verification gate that is intended to confirm user identity during registration or login flows. No specific CWE identifier has been assigned, but the behavior aligns with CWE-287 (Improper Authentication) (Feedly, Patchstack).
Successful exploitation allows an attacker to bypass the email verification requirement enforced by the plugin, potentially enabling unauthorized account creation or access to WordPress sites that rely on the plugin for user validation. The integrity impact is rated low, with no direct confidentiality or availability impact, meaning attackers can manipulate the verification state of accounts without necessarily gaining full system access. However, on sites where email verification is the primary access control gate, this bypass could allow fraudulent accounts to be activated and used for spam, privilege escalation attempts, or other malicious activity (Feedly).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.022% (0.000220), indicating a currently low probability of active exploitation in the wild. No evidence of in-the-wild exploitation, threat actor attribution, or CISA KEV catalog inclusion has been reported as of the available data. No public proof-of-concept exploit code has been identified (Feedly, Patchstack).
Users of the PickPlugins User Verification WordPress plugin should update to a version beyond 2.0.45 as soon as a patched release is made available by the vendor. In the interim, site administrators should consider disabling the plugin if email verification is not strictly required, or implement additional access controls (such as manual user approval) to compensate for the bypass risk. Monitoring WordPress user registration logs for unexpected account activations without corresponding email verification events is also recommended (Patchstack, Feedly).
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering March 23–29, 2026, highlighting it as part of a broader set of plugin security issues disclosed that week (Wordfence Blog). No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."