Email Verification and Authentication Bypass Vulnerability Affects WooCommerce Customers
CVE-2024-4185

8.1HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
30 April 2024

Summary

The Customer Email Verification for WooCommerce plugin for WordPress is susceptible to an Email Verification and Authentication Bypass vulnerability, affecting all versions up to and including version 2.7.4. This vulnerability arises from the utilization of an insufficiently random activation code, which allows unauthenticated attackers to circumvent email verification processes. Furthermore, if both options for 'Login the user automatically after the account is verified' and 'Verify account for current users' are enabled, attackers can potentially bypass authentication measures for previously registered users, raising serious security concerns for the integrity of user accounts.

Affected Version(s)

Customer Email Verification for WooCommerce * <= 2.7.4

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.