CVE-2026-14182

Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass

The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.


We have discovered 269 live websites that are affected by CVE-2026-14182.

Run a Free Instant Scan




Affected Software

Product  Customer Email Verification For Woocommerce
Category Wordpress Plugins
Vulnerable Domains269 live websites (88% of Customer Email Verification For Woocommerce install base)
Vulnerable Versions
  • from 2.4 through 3.2.6
Vulnerable Versions Count12 versions ( 67% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Revanth Hari Narayana Matte (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14182
United States86 websites



Germany25 websites
GB23 websites
India15 websites
France14 websites
South Africa14 websites
Canada9 websites
Australia6 websites
Spain6 websites
Cyprus6 websites

Website Distribution by TLD

Number of websites using CVE-2026-14182
.com134 websites
.co.uk21 websites
.de12 websites
.it8 websites
.ca6 websites
.fr6 websites
.com.au6 websites
.es4 websites
.nl3 websites
.net3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14182

Top websites that are affected by CVE-2026-14182. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com Bangladesh***,***
*****.com United States***,***
********.***.au Australia***,***
*************.com United States***,***
***********.**.za South Africa*,***,***
************.com GB*,***,***
***********.**.uk United States*,***,***
**********.com GB*,***,***
***************.com Canada*,***,***
*************.**.uk GB*,***,***
See full domain list

FAQ

CVE-2026-14182 is Improper Authentication in Customer Email Verification For Woocommerce
A total of 269 websites have been identified as vulnerable to CVE-2026-14182, based on global website indexing conducted by WebTechSurvey.
The Customer Email Verification For Woocommerce is affected by the CVE-2026-14182 vulnerability.
Customer Email Verification For Woocommerce versions up to 3.2.6 are vulnerable to CVE-2026-14182.
CVE-2026-14182 is resolved in version 3.2.6 of Customer Email Verification For Woocommerce.