What the vulnerability does
01Description
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, with Contributor-level access and above, to generate a verification link for any unverified user and log into the account. The 'Fine tune placement' option must be enabled in the plugin settings in order to exploit the vulnerability.
Explanation of Vulnerability in Simple Terms
02Summary
The Customer Email Verification for WooCommerce plugin through version 2.9.5 contains an authentication flaw that allows low-privileged users to gain unauthorized access to sensitive functionality. An attacker with a basic user account can bypass authentication checks to read, modify, or delete data without proper authorization. This affects the plugin's core email verification and user management features.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete sensitive site data by bypassing authentication checks with a low-privilege account.
Potential impact on your site
04Site Impact
Customer data, email verification records, and user accounts may be exposed, modified, or deleted by authenticated users with minimal privileges.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the WooCommerce site; no user interaction required.
Key dates
06Disclosure timeline
February 12, 2025
CVE published
April 8, 2026
Record updated