Description
WordPress Plugin User Verification is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently log in as any user. WordPress Plugin User Verification version 1.0.93 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.94 or latest
References
https://lana.codes/lanavdb/eeabe1d3-6f64-400a-8fb2-0865efdf6957/
https://sploitus.com/exploit?id=WPEX-ID:1EEE10A8-135F-4B76-8289-C381FF1F51EA
https://plugins.svn.wordpress.org/user-verification/trunk/readme.txt
Related Vulnerabilities
Moodle Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2023-28334)
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-33331)
Apache Tomcat 7PK - Security Features Vulnerability (CVE-2014-9635)
Python Improper Input Validation Vulnerability (CVE-2020-8315)
WordPress Plugin Custom Post Type UI 'wp-admin/admin.php' Cross-Site Scripting (0.7)