Impact
The vulnerability is caused by the Customer Email Verification for WooCommerce WordPress plugin failing to properly validate the email‑verification activation code. The plugin uses a loose type‑juggling comparison that an attacker can satisfy with a crafted non‑string value. This allows an unauthenticated attacker to trigger the verification process for any registered user who has not yet confirmed their email address, resulting in full account takeover. Once the attacker’s address is recorded as verified, they gain full control of the victim’s WordPress account, potentially accessing sensitive data, placing orders, or launching further attacks from the compromised account.
Affected Systems
The affected product is the WordPress plugin Customer Email Verification for WooCommerce. All releases prior to version 3.2.6 are vulnerable. The plugin is used in WooCommerce‑based online stores running WordPress, regardless of theme or other plugins.
Risk and Exploitability
The vulnerability can be exploited remotely by sending a crafted HTTP request to the plugin’s activation endpoint. No authentication is required, and the attack is performed over the public web interface. The CVSS score is not specified in the input, and the EPSS score is not available, so the exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known leveraged exploits at the time of reporting. Nevertheless, the high potential for account takeover warrants immediate attention.
OpenCVE Enrichment