What is CVE-2026-14861?
This vulnerability in the 'User Verification by PickPlugins' WordPress plugin (up to version 2.0.47) stems from a missing authorization check when resending verification emails. Unauthenticated attackers can reset the email-verification token for arbitrary users, potentially taking over accounts by bypassing the email verification step. Immediate plugin update is required to mitigate the risk.
Azərbaycanca: Bu zəiflik "User Verification by PickPlugins" WordPress pluginində (2.0.47-ə qədər versiyalar) autentifikasiya mexanizmindəki nöqsandan irəli gəlir. Doğrulanmamış hücumçulara icazəsiz yolla e-poçt doğrulama tokenini sıfırlamaq və təsdiq sorğusunu yenidən göndərmək imkanı verir ki, bu da istənilən istifadəçinin hesabına müdaxilə riski yaradır. Zəifliyin aradan qaldırılması üçün plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the 'User Verification by PickPlugins' plugin are affected by CVE-2026-14861?
This vulnerability affects the 'User Verification by PickPlugins' WordPress plugin up to version 2.0.47.
What can an attacker achieve by exploiting CVE-2026-14861?
Unauthenticated attackers can reset the email-verification token and resend the confirmation request, potentially taking over arbitrary user accounts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.