Recursos /
Plugins de WordPress /
User Verification by PickPlugins
SEGURIDAD DE PLUGINS
¿Es seguro User Verification by PickPlugins?
Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress User Verification by PickPlugins — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
Estado de mantenimiento
Vulnerabilidades conocidas
4 CVEs conocidos registrados para User Verification by PickPlugins.
Reportadas entre 2022 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-7458
|
User Verification by PickPlugins [user-verification] < 2.0.47 |
Elusión de autenticación mediante una ruta o canal alternativo |
Crítica
9,8
|
< 2.0.47
|
2.0.47 |
2026-05-01 |
—
|
|
CVE-2026-32497
|
User Verification by PickPlugins [user-verification] < 2.0.46 |
Weak Authentication |
Media
5,3
|
< 2.0.46
|
2.0.46 |
2026-03-23 |
—
|
|
CVE-2025-12374
|
User Verification by PickPlugins [user-verification] < 2.0.45 |
Autenticación indebida |
Crítica
9,8
|
< 2.0.45
|
2.0.45 |
2025-12-04 |
—
|
|
CVE-2022-4693
|
User Verification by PickPlugins [user-verification] < 1.0.94 |
Autenticación indebida |
Crítica
9,8
|
< 1.0.94
|
1.0.94 |
2022-12-28 |
—
|
CVE-2026-7458
The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-32497
The User Verification by PickPlugins plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.45. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-12374
The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.39. This is due to the plugin not properly validating that an OTP was generated before comparing it to user input in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting an empty OTP value.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-4693
Update the WordPress User Verification plugin to the latest available version (at least 1.0.94).
Lana Codes discovered and reported this Bypass Vulnerability vulnerability in WordPress User Verification Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. For example a way to bypass certain authorization checks which might allow a malicious actor to gain access to the admin panel. This vulnerability has been fixed in version 1.0.94.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Verifica tu propio sitio WordPress
Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.