CVE-2026-32497 Details
Description
Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45.
A weak authentication vulnerability has been identified in the PickPlugins User Verification WordPress plugin, specifically in versions through 2.0.45. This vulnerability allows for authentication abuse, potentially enabling unauthorized users to perform actions reserved for higher-privileged users, such as gaining admin access to a website.
Users of the PickPlugins User Verification WordPress plugin should update to version 2.0.46 or later. Patchstack users can enable auto-update for vulnerable plugins.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 25, 2026CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1390 | Weak Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PickPlugins User Verification | <= 2.0.45 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Mar 26, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | New CVE Received | [email protected] |
Volerion