plugin

Pie Register Vulnerabilities

56 known security issues reported for the Pie Register WordPress plugin. Most recent disclosed Jun 22, 2026.

7 critical 5 high 11 medium

Running Pie Register on your site? Check whether your installed version is affected.

Scan your site free

Pie Register – User Registration, Profiles & Content Restriction < 3.8.4.10 - Missing Authorization

medium

The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.8.4.10 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.8.4.10
Fixed in:
3.8.4.10
Disclosed:
Jun 22, 2026

CVE-2026-10530 on NVD →

Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization to Unauthenticated Registration Form Status Modification

medium

The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change registra...

CVSS:
6.5
Affected:
up to 3.8.4.8
Fixed in:
3.8.4.9
Disclosed:
Apr 3, 2026

CVE-2026-3571 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] <= 3.8.4.7 (unfixed)

unknown

[en] Missing Authorization vulnerability in Genetech Products Pie Register pie-register allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pie Register: from n/a through <= 3.8.4.7.

Affected:
up to 3.8.4.7
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24577 on NVD →

Pie Register <= 3.8.4.8 - Missing Authorization

medium

The Pie Register plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.8.4.8
Fixed in:
3.8.4.9
Disclosed:
Jan 20, 2026

CVE-2026-24577 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] <= 3.7.1.4 (unfixed)

unknown

[en] An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker c...

Affected:
up to 3.7.1.4
Fix:
No patched version reported
Disclosed:
Jul 9, 2025

CVE-2025-34077 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.8.4.1

unknown

[en] The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3.9 through publicly exposed log files. This makes it possible fo...

Affected:
up to 3.8.4.1
Fixed in:
3.8.4.1
Disclosed:
Feb 21, 2025

CVE-2024-13818 on NVD →

Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction <= 3.8.4 - Sensitive Information Exposure via Log Files

medium

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log files. This makes it possible for unaut...

CVSS:
5.3
Affected:
up to 3.8.4
Fixed in:
3.8.4.1
Disclosed:
Feb 20, 2025

CVE-2024-13818 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.8.3.5

unknown

[en] The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation/deactivation due to missing capability checks on the pieregister_install_addon,...

Affected:
up to 3.8.3.5
Fixed in:
3.8.3.5
Disclosed:
Jul 9, 2024

CVE-2024-6069 on NVD →

Pie Register - Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation

high

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pieregister_install_addon function in all versions up to, a...

CVSS:
8.8
Affected:
up to 3.8.3.4
Fixed in:
3.8.3.5
Disclosed:
Jul 8, 2024

CVE-2024-6069 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 1.7.8

unknown

[en] The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.7. This is due to insufficient verification on the user being supplied during a social login through the plugin. This makes it possible for unauthenticated attackers to l...

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
May 24, 2024

CVE-2024-4544 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.8.3.3

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.

Affected:
up to 3.8.3.3
Fixed in:
3.8.3.3
Disclosed:
Mar 17, 2024

CVE-2024-27957 on NVD →

Pie Register <= 3.8.3.2 - Unauthenticated Arbitrary File Upload

critical

The Pie Register plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pie_save_registration function in versions up to, and including, 3.8.3.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make r...

CVSS:
9.8
Affected:
up to 3.8.3.2
Fixed in:
3.8.3.3
Disclosed:
Mar 13, 2024

CVE-2024-27957 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.8.2.3

unknown

[en] The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

Affected:
up to 3.8.2.3
Fixed in:
3.8.2.3
Disclosed:
Feb 27, 2023

CVE-2023-0552 on NVD →

Pie Register <= 3.8.2.2 - Open Redirect

medium

The Pie Register plugin for WordPress is vulnerable to Open Redirect via the 'redirect_to' parameter in versions up to, and including, 3.8.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to redirect users to an external site, if they can successfully...

CVSS:
6.1
Affected:
up to 3.8.2.2
Fixed in:
3.8.2.3
Disclosed:
Feb 6, 2023

CVE-2023-0552 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.8.1.3

unknown

[en] The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

Affected:
up to 3.8.1.3
Fixed in:
3.8.1.3
Disclosed:
Dec 19, 2022

CVE-2022-4024 on NVD →

Pie Register <= 3.8.1.2 - Missing Authorization to Arbitrary User Deletion

medium

The Pie Register plugin for WordPress is vulnerable to arbitrary user deletion in versions up to, and including, 3.8.1.3. This is due to missing validation and capability checking on code that handles the deletion of users. This makes it possible for unauthenticated attackers to delete arbitrary users.

CVSS:
6.5
Affected:
up to 3.8.1.2
Fixed in:
3.8.1.3
Disclosed:
Nov 28, 2022

CVE-2022-4024 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.7.1.6

unknown

[en] The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

Affected:
up to 3.7.1.6
Fixed in:
3.7.1.6
Disclosed:
Nov 8, 2021

CVE-2021-24647 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.7.1.6

unknown

[en] The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

Affected:
up to 3.7.1.6
Fixed in:
3.7.1.6
Disclosed:
Nov 8, 2021

CVE-2021-24731 on NVD →

Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments <= 3.7.2.3 - Open Redirect

medium

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 3.7.2.3. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible f...

CVSS:
6.1
Affected:
up to 3.7.2.4
Fixed in:
3.7.2.4
Disclosed:
Oct 21, 2021

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.7.2.4

unknown

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 3.7.2.3. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible f...

Affected:
up to 3.7.2.4
Fixed in:
3.7.2.4
Disclosed:
Oct 21, 2021

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.7.2.4

unknown

Open Redirect vulnerability discovered by WPScanTeam in WordPress Pie Register plugin (versions <= 3.7.2.3).

Affected:
up to 3.7.2.4
Fixed in:
3.7.2.4
Disclosed:
Oct 21, 2021

Pie Register <= 3.7.1.5 - Unauthenticated SQL Injection

critical

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

CVSS:
9.8
Affected:
up to 3.7.1.6
Fixed in:
3.7.1.6
Disclosed:
Oct 11, 2021

CVE-2021-24731 on NVD →

Pie Register <= 3.7.1.4 - Authentication Bypass

critical

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.7.1.4. This is due to the plugin not properly validating the identity of a user p...

CVSS:
9.8
Affected:
up to 3.7.1.4
Fixed in:
3.7.1.5
Disclosed:
Oct 11, 2021

CVE-2025-34077 on NVD →

Pie Register <= 3.7.1.5 - Authentication Bypass

high

The Registration Forms User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

CVSS:
8.1
Affected:
up to 3.7.1.6
Fixed in:
3.7.1.6
Disclosed:
Oct 11, 2021

CVE-2021-24647 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.7.0.1

unknown

[en] The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.

Affected:
up to 3.7.0.1
Fixed in:
3.7.0.1
Disclosed:
Apr 22, 2021

CVE-2021-24239 on NVD →

Pie Register – User Registration Forms <= 3.7.0.0 - Reflected Cross-Site Scripting

medium

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.

CVSS:
6.1
Affected:
up to 3.7.0.1
Fixed in:
3.7.0.1
Disclosed:
Apr 3, 2021

CVE-2021-24239 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.1.2

unknown

[en] The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Aug 27, 2019

CVE-2019-15659 on NVD →

Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments < 3.1.2 - SQL Injection

critical

The Pie Register plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions before 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

CVSS:
9.8
Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jul 3, 2019

CVE-2019-15659 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.0.18

unknown

Unauthenticated Cross-Site Scripting (XSS) vulnerability found by Alvaro J. Gene in WordPress Pie Register plugin (versions <= 3.0.17).

Affected:
up to 3.0.18
Fixed in:
3.0.18
Disclosed:
Oct 29, 2018

Pie Register < 3.0.18 - Unauthenticated Cross-Site Scripting

high

The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.0.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.1
Affected:
up to 3.0.18
Fixed in:
3.0.18
Disclosed:
Oct 24, 2018

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.0.18

unknown

The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.0.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 3.0.18
Fixed in:
3.0.18
Disclosed:
Oct 24, 2018

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.0.10

unknown

Authenticated Blind SQL Injection (SQLi) vulnerability found by Manuel Garcia Cardenas WordPress Pie Register plugin (versions <= 3.0.9).

Affected:
up to 3.0.10
Fixed in:
3.0.10
Disclosed:
Jun 20, 2018

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.0.10

unknown

[en] SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.

Affected:
up to 3.0.10
Fixed in:
3.0.10
Disclosed:
Jun 17, 2018

CVE-2018-10969 on NVD →

Pie Register <= 3.0.9 - SQL Injection

critical

Blind SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.

CVSS:
9.8
Affected:
up to 3.0.9
Fixed in:
3.0.10
Disclosed:
Jun 12, 2018

CVE-2018-10969 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.19

unknown

[en] Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.

Affected:
up to 2.0.19
Fixed in:
2.0.19
Disclosed:
Oct 16, 2015

CVE-2015-7377 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.19

unknown

[en] Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin....

Affected:
up to 2.0.19
Fixed in:
2.0.19
Disclosed:
Oct 16, 2015

CVE-2015-7682 on NVD →

Pie Register – User Registration Forms < 2.0.19 - Authenticated SQL Injection

medium

Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.

CVSS:
6.3
Affected:
up to 2.0.19
Fixed in:
2.0.19
Disclosed:
Oct 12, 2015

CVE-2015-7682 on NVD →

Pie Register – User Registration Forms < 2.0.19 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.

CVSS:
6.1
Affected:
up to 2.0.19
Fixed in:
2.0.19
Disclosed:
Oct 12, 2015

CVE-2015-7377 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.16

unknown

This plugin is prone to an privilege escalation vulnerability. Update the plugin.

Affected:
up to 2.0.16
Fixed in:
2.0.16
Disclosed:
Jul 4, 2015

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.16

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 2.0.16
Fixed in:
2.0.16
Disclosed:
Jul 4, 2015

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.15

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.0.15
Fixed in:
2.0.15
Disclosed:
Jul 4, 2015

Registration Forms – User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations for WordPress 2.0.14 - 2.0.15 - Authentication Bypass

critical

The Registration Forms – User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations plugin for WordPress is vulnerable to authentication bypass in versions 2.0.14 - 2.0.15 . This is due to a lack of validation of user input in a login request to the plugin. This makes it possible for unauthentic...

CVSS:
9.8
Affected:
2.0.14 – 2.0.15
Fixed in:
2.0.16
Disclosed:
May 4, 2015

Pie Register 2.0.14-2.0.15 - SQL Injection

critical

The Pie Register plugin for WordPress is vulnerable to SQL Injection via the show_dash_widget’ and ‘invitaion_code’ parameter in versions 2.0.14-2.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

CVSS:
9.8
Affected:
2.0.14 – 2.0.15
Fixed in:
2.0.16
Disclosed:
May 4, 2015

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] >= 2.0.14 - <= 2.0.15

unknown

The Pie Register plugin for WordPress is vulnerable to SQL Injection via the show_dash_widget’ and ‘invitaion_code’ parameter in versions 2.0.14-2.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

Affected:
2.0.14 – 2.0.15
Fixed in:
2.0.15
Disclosed:
May 4, 2015

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] >= 2.0.14 - <= 2.0.15

unknown

The Registration Forms – User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations plugin for WordPress is vulnerable to authentication bypass in versions 2.0.14 - 2.0.15 . This is due to a lack of validation of user input in a login request to the plugin. This makes it possible for unauthentic...

Affected:
2.0.14 – 2.0.15
Fixed in:
2.0.15
Disclosed:
May 4, 2015

Pie Register < 2.0.15 - Cross-Site Scripting

high

The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting via the 'notice' parameter in versions before 2.0.15 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.1
Affected:
up to 2.0.15
Fixed in:
2.0.15
Disclosed:
Mar 9, 2015

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.15

unknown

The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting via the 'notice' parameter in versions before 2.0.15 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.0.15
Fixed in:
2.0.15
Disclosed:
Mar 9, 2015

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.14

unknown

[en] The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

Affected:
up to 2.0.14
Fixed in:
2.0.14
Disclosed:
Jan 23, 2015

CVE-2014-8802 on NVD →

Pie Register <= 2.0.13 - Missing Authorization

high

The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

CVSS:
7.3
Affected:
up to 2.0.13
Fixed in:
2.0.14
Disclosed:
Jan 17, 2015

CVE-2014-8802 on NVD →

Pie Register <= 1.30 - Multiple Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a re...

CVSS:
6.1
Affected:
up to 1.30
Fixed in:
1.31
Disclosed:
Aug 1, 2014

CVE-2013-4954 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 1.31

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in...

Affected:
up to 1.31
Fixed in:
1.31
Disclosed:
Jul 29, 2013

CVE-2013-4954 on NVD →

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.7.2.4

unknown

The plugin passes unvalidated user input to the wp_redirect() function, without validating it, leading to an Open redirect issue

Affected:
up to 3.7.2.4
Fixed in:
3.7.2.4

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 3.0.18

unknown

The Pie Register &ndash; User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin was affected by an Unauthenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 3.0.18
Fixed in:
3.0.18

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.16

unknown

User input is not validated correctly when accepting a login request via the Pie Register plugin. It is possible to manipulate posted variables in order to login using an arbitrary User ID (such as 1, for the default Administrative account).

Affected:
up to 2.0.16
Fixed in:
2.0.16

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.16

unknown

User input is not validated correctly when accepting an Invitation Code, as such an SQL Injection attack is possible. This attack is triggered when the parameters &lsquo;show_dash_widget&rsquo; and &lsquo;invitaion_code&rsquo; are provided to any page, by any user (anonymous or otherwise).

Affected:
up to 2.0.16
Fixed in:
2.0.16

Pie Register – User Registration, Profiles &amp; Content Restriction [pie-register] < 2.0.15

unknown

The Pie Register &ndash; User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.0.15
Fixed in:
2.0.15

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database