low · CVSS v3 3.7 · EPSS 0.00139
CVE-2026-96962
The Pie Register WordPress plugin (v3.8.4.13 and earlier) fails to restrict access to its invitation‑code report. An unauthenticated attacke
Overview
The Pie Register WordPress plugin (v3.8.4.13 and earlier) fails to restrict access to its invitation‑code report. An unauthenticated attacker who knows a valid invitation code can retrieve the usernames and email addresses of all users who registered with that code. This exposes personal data and can aid further phishing or credential‑replay attacks.
Description
The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.
Impact
Confidentiality: The attacker can view usernames and email addresses of all users who registered with a known invitation code. Integrity: No direct impact, but data exposure can lead to credential stuffing. Availability: No impact. Defenders: site administrators, security teams, and users whose data may be exposed.
Remediation
Update the Pie Register plugin to version 3.8.4.14 or later, which enforces authentication for the invitation‑code report. If immediate update is not possible, restrict access to the report URL via .htaccess or web‑application firewall rules, and invalidate any invitation codes that may have been exposed. Monitor user registration logs for suspicious activity.
Risk context
Severity is low (CVSS 3.7) and EPSS is 0.00139, indicating a very low probability of exploitation. However, the data exposed is personally identifiable information, so defenders should still address the issue promptly.
Affected products
- Pie Register WordPress plugin v3.8.4.13
- Pie Register WordPress plugin v3.8.4.12
- Pie Register WordPress plugin v3.8.4.11
- Pie Register WordPress plugin v3.8.4.10
- Pie Register WordPress plugin v3.8.4.9
- Pie Register WordPress plugin v3.8.4.8
- Pie Register WordPress plugin v3.8.4.7
- Pie Register WordPress plugin v3.8.4.6
Scores
- Severity
- low
- CVSS v2
- 2.6
- CVSS v3
- 3.7
- CVSS v4
- —
- EPSS
- 0.00139