CVE-2026-7458Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin" function. This makes it possible for unauthenticated attackers to log in as any user with a verified email address, such as an administrator, by submitting a "true" OTP value.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-02); latest day: 4
  • 10 total mentions across 4 days

Deep dive

Activity timeline10 mentions / 4d
01234Mentions · 2026-05-02: 4Mentions · 2026-05-09: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 4Exploit Tool / Code · 2026-05-09: 1Patch / Workaround · 2026-05-02: 3Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-02: 4Technical Details · 2026-05-09: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 305-0205-0905-1305-14
Signal classification4 categories
Disclosure
550.0%
Patch
330.0%
Exploit
110.0%
General
110.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-024
Disclosure2Patch2
2026-05-091
Exploit1
2026-05-131
Patch1
2026-05-144
Disclosure3General1
Full discourse10 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🚨 تنبيه لأصحاب مواقع ومدونات (WordPress) إذا تستخدم أي من هذي الإضافات، حدثها فوراً! لأنها مصابة بثغرات حرجة جداً بتقييم (CVSS: 9.8). الإضافات المصابة: 1️⃣ إضافة (Temporary Login) | الثغرة: CVE-2026-7567 2️⃣ إضافة (User Registration) | الثغرة: CVE-2026-4882 3️⃣ إضافة (User Verification) | الثغرة: CVE-2026-7458

    Post summary

    The announcement warns that three WordPress plugins have critical vulnerabilities (CVSS 9.8) and urges site owners to update them immediately to mitigate the risk.

    1301482.5K
    49.3K followersView on X
  • SwissWPSecure@Swisswpsecure
    Exploit

    An OTP login plugin had one job: verify users before letting them in. The verification check passes if you type "true." CVE-2026-7458. CVSS 9.8. Published May 2, 2026. Zero credentials required.

    Post summary

    CVE-2026-7458 is a high‑severity flaw in an OTP login plugin that allows credential‑less bypass by submitting "true"; no patch or mitigation is mentioned and no in‑the‑wild activity is reported.

    5001033
    1 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7458 — CVSS 9.8/10 ██████████ The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/JVaKMlXqA2

    Post summary

    The tweet announces the critical CVE-2026-7458 affecting the PickPlugins User Verification plugin, notes an authentication bypass, and urges users to apply an available patch.

    1001094
    26 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7458 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46.

    Post summary

    The text announces CVE‑2026‑7458 as a critical authentication bypass in the PickPlugins WordPress plugin up to version 2.0.46, providing CVSS and severity details but no PoC, exploit code, patch, or evidence of active exploitation.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-7458 (CVSS 9.8) — multiple products. CVE: CVE-2026-7458 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-7458 as a critical vulnerability with its CVSS rating and severity status, but provides no evidence of PoC, exploit code, active use, or available patch.

    1000040
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-7458 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory lists the CVE, CVSS, and severity but provides no PoC, exploit, patch, or activity details.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7458-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text includes only a link and generic hashtags without detailed information about the CVE.

    0000027
    210 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical vulnerability (CVE-2026-7458) affects the User Verification by PickPlugins for WordPress, allowing attackers to bypass OTP authentication and access accounts with verified emails. If you use this plugin, update immediately to protect your data. #Cybersecurity

    Post summary

    CVE-2026-7458 is a critical flaw in the WordPress User Verification plugin that permits OTP bypass; users should update the plugin immediately to mitigate the risk.

    0000043
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7458 Authentication Bypass in PickPlugins User Verification Plugin for WordPress 2.0.46 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7458

    Post summary

    A new authentication bypass vulnerability (CVE-2026-7458) has been disclosed for PickPlugins User Verification Plugin, but no exploitation evidence or remediation is provided.

    0000060
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-7458 The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to,… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-7458 #WordPress #CyberSecurity #InfoSec

    Post summary

    A critical authentication bypass vulnerability (CVE-2026-7458) in the PickPlugins WordPress plugin has been disclosed with a CVSS score of 9.8, and no patch is available yet.

    0000055
    458 followersView on X

Explore more