{"id":"CVE-2026-44584","title":"Paymenter doesn't reset email verification status after email change","summary":"Paymenter doesn't reset email verification status after email change","severity":"medium","cvss":4.3,"cwe":["CWE-287"],"vendor":"paymenter","product":"paymenter/paymenter","ecosystem":"composer","affected":["paymenter/paymenter < 1.5.0"],"patched":["paymenter/paymenter 1.5.0"],"published":"2026-06-22","updated":"2026-06-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-rv89-wch8-c574","references":[{"url":"https://github.com/Paymenter/Paymenter/security/advisories/GHSA-rv89-wch8-c574"},{"url":"https://github.com/advisories/GHSA-rv89-wch8-c574"}],"tags":["ghsa","composer"],"ingestedAt":"2026-06-29T13:24:35.512Z","epss":0.00163,"epssPercentile":0.05908,"slug":"CVE-2026-44584","body":"## Overview\n\n### Summary\nThe email update functionality fails to invalidate the existing verification state when a user changes their email address, allowing a verified account to retain its verified status after switching to an unverified or unowned email address.\n\n### Technical Details\nWhen a user updated their email address, the system did not reset or revalidate the associated email verification status. As a result, the verification column remained set to “true” even after the email address was changed.\n\nThis allowed an attacker to:\n\n- Verify an account using a legitimate email address\n- Change the account email to an arbitrary or unowned address\n- Retain the verified status without re-confirmation of the new email\n\nNo verification challenge or confirmation was required for the newly assigned email address.\n\n### Impact\nThis vulnerability allows a user to associate a verified account with an email address they do not control, this may result in:\n\n- Misrepresentation of email ownership\n- Bypass of verification-based trust assumptions\n- Potential abuse of features gated behind verified status\n\nNo direct unauthorized access to other users accounts or data is possible through this issue alone.\n\n## Affected packages\n\n- `paymenter/paymenter < 1.5.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `paymenter/paymenter 1.5.0`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}