Email Verification and Authentication Bypass Vulnerability Affects WooCommerce Customers
CVE-2024-4185
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 30 April 2024
What is CVE-2024-4185?
The Customer Email Verification for WooCommerce plugin for WordPress is susceptible to an Email Verification and Authentication Bypass vulnerability, affecting all versions up to and including version 2.7.4. This vulnerability arises from the utilization of an insufficiently random activation code, which allows unauthenticated attackers to circumvent email verification processes. Furthermore, if both options for 'Login the user automatically after the account is verified' and 'Verify account for current users' are enabled, attackers can potentially bypass authentication measures for previously registered users, raising serious security concerns for the integrity of user accounts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Customer Email Verification for WooCommerce * <= 2.7.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved