CVE-2026-7458: User Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint
The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "userverificationformwrapprocessotpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: User Verification by PickPluginsto a version that resolves this vulnerability.Fixed in 2.0.46
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7458?
CVE-2026-7458 has a high severity rating due to its ability to allow unauthenticated authentication bypass.
How do I fix CVE-2026-7458?
To fix CVE-2026-7458, update the User Verification by PickPlugins plugin to version 2.0.47 or later.
Which versions are affected by CVE-2026-7458?
CVE-2026-7458 affects all versions of the User Verification by PickPlugins plugin up to and including 2.0.46.
What are the implications of CVE-2026-7458?
CVE-2026-7458 can allow attackers to bypass authentication and gain unauthorized access to the WordPress site.
Who are the affected users of CVE-2026-7458?
Users of the User Verification by PickPlugins plugin for WordPress who are using versions up to 2.0.46 are affected by CVE-2026-7458.