What is CVE-2026-14182?
This vulnerability exists in the Customer Email Verification for WooCommerce WordPress plugin before version 3.2.6 due to improper validation of the email verification activation code. An unauthenticated attacker can exploit a 'loose comparison' by sending a crafted value type, allowing them to verify and take over an account. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: Bu zəiflik, Customer Email Verification for WooCommerce WordPress plugin-inin 3.2.6-dan əvvəlki versiyalarında email təsdiqləmə aktivasiya kodunun düzgün yoxlanılmaması səbəbindən yaranır. Autentifikasiya olunmamış hücumçu 'loose comparison' məntiqindən istifadə edərək xüsusi hazırlanmış dəyər tipi ilə kodu keçə bilər və hesabı ələ keçirə bilər. Plugin-i dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendors: WooCommerce, WordPress
FAQ2
In which WordPress plugin was the vulnerability discovered?
The CVE-2026-14182 vulnerability exists in the Customer Email Verification for WooCommerce plugin.
What can an attacker achieve by exploiting this vulnerability?
An unauthenticated attacker can bypass the email verification code by exploiting the 'loose comparison' logic and take over the target account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.