Wisetr develops a focused WordPress plugin for user email verification in WooCommerce environments, with disclosed vulnerabilities centered on authentication and access-control deficiencies. The recurring weakness pattern—authentication bypass via alternate channels, improper access controls, and missing authentication on critical functions—reflects the plugin's role in handling user identity verification and account access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wisetr over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2781CRITICAL The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This | Jun 3, 2023 | 9.8 | 29 | NO | NO |
CVE-2018-21007CRITICAL The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads. | Aug 29, 2019 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wisetr.
Media articles that mention a CVE ID that affects a product developed by Wisetr — matched by CVE ID, not by vendor name.