CVE · Critical

CVE-2026-7458 — User Verification by PickPlugins [user-verification] < 2.0.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-7458 User Verification by PickPlugins [user-verification] < 2.0.47 Authentication Bypass Using an Alternate Path or Channel Critical 9.8 < 2.0.47 2.0.47 2026-05-01

CVE-2026-7458

The User Verification plugin for WordPress contains a flaw that allows unauthorized access due to incorrect verification of One-Time Password codes. Specifically, the function handling OTP login submissions uses a weak comparison method, allowing attackers to bypass authentication checks and gain access to any user account with a verified email address. This vulnerability affects all versions up to 2.0.46.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.