CVE-2026-14182: Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14182?
The severity of CVE-2026-14182 is rated at 80, indicating a high risk of exploitation.
How do I fix CVE-2026-14182?
To fix CVE-2026-14182, update the Customer Email Verification for WooCommerce plugin to version 3.2.6 or later.
What type of vulnerability is CVE-2026-14182?
CVE-2026-14182 is an unauthenticated account takeover vulnerability due to an authentication bypass.
Which software is affected by CVE-2026-14182?
CVE-2026-14182 affects the Customer Email Verification for WooCommerce WordPress plugin.
What is the impact of CVE-2026-14182 on WordPress sites?
CVE-2026-14182 allows unauthenticated attackers to verify accounts and take over user accounts, posing a serious security risk.