CVE-2026-14182
9.8WooCommerce · Customer Email Verification
The Customer Email Verification for WooCommerce plugin allows unauthenticated users to hijack accounts due to a loose comparison in the email verification process.
Executive summary
An authentication bypass vulnerability in the Customer Email Verification for WooCommerce plugin allows unauthenticated attackers to hijack user accounts.
Vulnerability
The plugin utilizes a loose comparison during the validation of email activation codes (CWE-287). This flaw allows an unauthenticated attacker to craft a specific value type that satisfies the verification check, effectively hijacking accounts that have not yet confirmed their email address.
Business impact
With a CVSS score of 9.8 (Critical), this vulnerability presents a high risk of unauthorized account access. Attackers can gain control over user accounts, potentially leading to identity theft, unauthorized data access, and erosion of customer trust in the platform's security.
Remediation
Immediate Action: Update the Customer Email Verification for WooCommerce plugin to version 3.2.6 or later immediately.
Proactive Monitoring: Review user account modification logs for suspicious activity or accounts that have had their email verification status changed unexpectedly.
Compensating Controls: Disable new user registrations or email verification processes until the plugin update is successfully applied.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
This vulnerability is highly critical due to the potential for widespread account takeover. Organizations using this plugin must verify their current version and apply the update to version 3.2.6 without delay to prevent unauthorized access.