CVE-2026-14861: Unknown User Verification By Pickplugins
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.
Affected products
- Unknown User Verification By Pickplugins: up to and including 2.0.47
Published 2026-08-19. Last modified 2026-08-26.