The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default value is empty, and the not empty check is missing in the 'eb_user_email_verify' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This can only be exploited if the 'Email Verification' setting is enabled.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default value is empty, and the not empty check is missing in the 'eb_user_email_verify' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This can only be exploited if the 'Email Verification' setting is enabled. | The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default value is empty, and the not empty check is missing in the 'eb_user_email_verify' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This can only be exploited if the 'Email Verification' setting is enabled. |
| Title | Edwiser Bridge <= 3.0.5 - Authentication Bypass due to Missing Empty Value Check | |
| Weaknesses | CWE-288 |
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-05-07T05:32:58.532Z
Updated: 2026-04-08T16:58:38.790Z
Reserved: 2024-04-25T14:30:11.072Z
Link: CVE-2024-4186
Updated: 2024-08-01T20:33:52.547Z
Status : Awaiting Analysis
Published: 2024-05-07T06:15:09.380
Modified: 2026-04-08T18:21:41.907
Link: CVE-2024-4186
No data.