CVE-2022-4693
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
23/01/2023
Last modified:
02/04/2025
Description
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pickplugins:user_verification:*:*:*:*:*:wordpress:*:* | 1.0.94 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



