WordPress Customer Email Verification for WooCommerce是WordPress基金会开源的一款验证客户电子邮箱的插件。 WordPress Customer Email Verification for WooCommerce 3.2.6之前版本存在授权问题漏洞,该漏洞源于未正确验证邮箱验证激活码,依赖宽松比较,攻击者可通过构造的值类型满足验证,导致未经身份验证的用户能够验证并接管任意未确认邮箱的注册用户账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Customer Email Verification for WooCommerce | 2.4.0< 3.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Customer Email Verification for WooCommerce | 2.4.0 ~ 3.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15413 | 10.0 CRITICAL | Link Factory - Backdoor |
| CVE-2026-14332 | 5.4 MEDIUM | Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via |
| CVE-2026-14213 | Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR | |
| CVE-2026-13328 | TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification | |
| CVE-2026-13610 | KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration | |
| CVE-2026-18945 | WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation v | |
| CVE-2026-19088 | ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication |
No comments yet