CVE-2024-13528: Customer Email Verification for WooCommerce <= 2.9.5 - Authentication Bypass via Shortcode
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, with Contributor-level access and above, to generate a verification link for any unverified user and log into the account. The 'Fine tune placement' option must be enabled in the plugin settings in order to exploit the vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13528?
CVE-2024-13528 has a high severity rating due to its potential for authentication bypass.
How do I fix CVE-2024-13528?
To fix CVE-2024-13528, update the Customer Email Verification for WooCommerce plugin to version 2.9.6 or later.
What versions are affected by CVE-2024-13528?
CVE-2024-13528 affects all versions of the Customer Email Verification for WooCommerce plugin up to and including 2.9.5.
What kind of vulnerability is CVE-2024-13528?
CVE-2024-13528 is classified as an Authentication Bypass vulnerability.
Who is impacted by CVE-2024-13528?
Websites using the vulnerable Customer Email Verification for WooCommerce plugin on WordPress installations are impacted by CVE-2024-13528.