Vulnerabilities and security researches foruser-verification user-verification
Direction: descendingDec 11, 2025
User Verification # CVE-2025-12374
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 05, 2025
- Research Description
- The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.39. This is due to the plugin not properly validating that an OTP was generated before comparing it to user input in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting an empty OTP value.
- Affected versions
-
max 2.0.39.
- Status
-
vulnerable
Jun 06, 2024
User Verification # CVE-2022-4693
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 23, 2023
- Research Description
- The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website.
- Affected versions
-
max 1.0.94.
- Status
-
vulnerable