WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro User Verification by PickPlugins?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress User Verification by PickPlugins — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: user-verification

Estado de mantenimiento

Vulnerabilidades conocidas

4 CVEs conocidos registrados para User Verification by PickPlugins. Reportadas entre 2022 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-7458 User Verification by PickPlugins [user-verification] < 2.0.47 Elusión de autenticación mediante una ruta o canal alternativo Crítica 9,8 < 2.0.47 2.0.47 2026-05-01
CVE-2026-32497 User Verification by PickPlugins [user-verification] < 2.0.46 Weak Authentication Media 5,3 < 2.0.46 2.0.46 2026-03-23
CVE-2025-12374 User Verification by PickPlugins [user-verification] < 2.0.45 Autenticación indebida Crítica 9,8 < 2.0.45 2.0.45 2025-12-04
CVE-2022-4693 User Verification by PickPlugins [user-verification] < 1.0.94 Autenticación indebida Crítica 9,8 < 1.0.94 1.0.94 2022-12-28

CVE-2026-7458

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-32497

The User Verification by PickPlugins plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.45. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-12374

The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.39. This is due to the plugin not properly validating that an OTP was generated before comparing it to user input in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting an empty OTP value.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-4693

Update the WordPress User Verification plugin to the latest available version (at least 1.0.94). Lana Codes discovered and reported this Bypass Vulnerability vulnerability in WordPress User Verification Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. For example a way to bypass certain authorization checks which might allow a malicious actor to gain access to the admin panel. This vulnerability has been fixed in version 1.0.94.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.