rootpwn

low · CVSS v3 3.7 · EPSS 0.00139

CVE-2026-96962

The Pie Register WordPress plugin (v3.8.4.13 and earlier) fails to restrict access to its invitation‑code report. An unauthenticated attacke

Overview

The Pie Register WordPress plugin (v3.8.4.13 and earlier) fails to restrict access to its invitation‑code report. An unauthenticated attacker who knows a valid invitation code can retrieve the usernames and email addresses of all users who registered with that code. This exposes personal data and can aid further phishing or credential‑replay attacks.

Description

The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.

Impact

Confidentiality: The attacker can view usernames and email addresses of all users who registered with a known invitation code. Integrity: No direct impact, but data exposure can lead to credential stuffing. Availability: No impact. Defenders: site administrators, security teams, and users whose data may be exposed.

Remediation

Update the Pie Register plugin to version 3.8.4.14 or later, which enforces authentication for the invitation‑code report. If immediate update is not possible, restrict access to the report URL via .htaccess or web‑application firewall rules, and invalidate any invitation codes that may have been exposed. Monitor user registration logs for suspicious activity.

Risk context

Severity is low (CVSS 3.7) and EPSS is 0.00139, indicating a very low probability of exploitation. However, the data exposed is personally identifiable information, so defenders should still address the issue promptly.

Affected products

  • Pie Register WordPress plugin v3.8.4.13
  • Pie Register WordPress plugin v3.8.4.12
  • Pie Register WordPress plugin v3.8.4.11
  • Pie Register WordPress plugin v3.8.4.10
  • Pie Register WordPress plugin v3.8.4.9
  • Pie Register WordPress plugin v3.8.4.8
  • Pie Register WordPress plugin v3.8.4.7
  • Pie Register WordPress plugin v3.8.4.6

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
—
EPSS
0.00139

WordPress Plugin Data Exposure Invitation Code Low Severity PII Access Control

← All CVEs