Metrics
Affected Vendors & Products
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 18 Feb 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpfactory
Wpfactory customer Email Verification For Woocommerce |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:wpfactory:customer_email_verification_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpfactory
Wpfactory customer Email Verification For Woocommerce |
Wed, 12 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Feb 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, with Contributor-level access and above, to generate a verification link for any unverified user and log into the account. The 'Fine tune placement' option must be enabled in the plugin settings in order to exploit the vulnerability. | |
Title | Customer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcode | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-12T14:38:45.364Z
Reserved: 2025-01-17T23:24:53.274Z
Link: CVE-2024-13528

Updated: 2025-02-12T14:38:14.204Z

Status : Analyzed
Published: 2025-02-12T10:15:12.130
Modified: 2025-02-18T18:53:58.897
Link: CVE-2024-13528

No data.

No data.