CVE-2024-4185

HIGH

Customer Email Verification for WooCommerce <2.7.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and if both the "Login the user automatically after the account is verified" and "Verify account for current users" options are checked, then it potentially makes it possible for attackers to bypass authentication for other users.

Scores

CVSS v3 8.1
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-330
Status published
Products (2)
algoritmika/Customer Email Verification for WooCommerce < 2.7.4
wpcodefactory/Customer Email Verification for WooCommerce < 2.7.4
Published Apr 30, 2024
Tracked Since Feb 18, 2026