Pie Register – User Registration, Profiles & Content Restriction < 3.8.4.10 - Missing Authorization
medium
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.8.4.10 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.8.4.10
- Fixed in:
- 3.8.4.10
- Disclosed:
- Jun 22, 2026
CVE-2026-10530 on NVD →
Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization to Unauthenticated Registration Form Status Modification
medium
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change registra...
- CVSS:
- 6.5
- Affected:
- up to 3.8.4.8
- Fixed in:
- 3.8.4.9
- Disclosed:
- Apr 3, 2026
CVE-2026-3571 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] <= 3.8.4.7 (unfixed)
unknown
[en] Missing Authorization vulnerability in Genetech Products Pie Register pie-register allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pie Register: from n/a through <= 3.8.4.7.
- Affected:
- up to 3.8.4.7
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24577 on NVD →
Pie Register <= 3.8.4.8 - Missing Authorization
medium
The Pie Register plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.8.4.8
- Fixed in:
- 3.8.4.9
- Disclosed:
- Jan 20, 2026
CVE-2026-24577 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] <= 3.7.1.4 (unfixed)
unknown
[en] An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker c...
- Affected:
- up to 3.7.1.4
- Fix:
- No patched version reported
- Disclosed:
- Jul 9, 2025
CVE-2025-34077 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.8.4.1
unknown
[en] The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3.9 through publicly exposed log files. This makes it possible fo...
- Affected:
- up to 3.8.4.1
- Fixed in:
- 3.8.4.1
- Disclosed:
- Feb 21, 2025
CVE-2024-13818 on NVD →
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction <= 3.8.4 - Sensitive Information Exposure via Log Files
medium
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log files. This makes it possible for unaut...
- CVSS:
- 5.3
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4.1
- Disclosed:
- Feb 20, 2025
CVE-2024-13818 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.8.3.5
unknown
[en] The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation/deactivation due to missing capability checks on the pieregister_install_addon,...
- Affected:
- up to 3.8.3.5
- Fixed in:
- 3.8.3.5
- Disclosed:
- Jul 9, 2024
CVE-2024-6069 on NVD →
Pie Register - Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
high
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pieregister_install_addon function in all versions up to, a...
- CVSS:
- 8.8
- Affected:
- up to 3.8.3.4
- Fixed in:
- 3.8.3.5
- Disclosed:
- Jul 8, 2024
CVE-2024-6069 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 1.7.8
unknown
[en] The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.7. This is due to insufficient verification on the user being supplied during a social login through the plugin. This makes it possible for unauthenticated attackers to l...
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- May 24, 2024
CVE-2024-4544 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.8.3.3
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.
- Affected:
- up to 3.8.3.3
- Fixed in:
- 3.8.3.3
- Disclosed:
- Mar 17, 2024
CVE-2024-27957 on NVD →
Pie Register <= 3.8.3.2 - Unauthenticated Arbitrary File Upload
critical
The Pie Register plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pie_save_registration function in versions up to, and including, 3.8.3.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make r...
- CVSS:
- 9.8
- Affected:
- up to 3.8.3.2
- Fixed in:
- 3.8.3.3
- Disclosed:
- Mar 13, 2024
CVE-2024-27957 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.8.2.3
unknown
[en] The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability
- Affected:
- up to 3.8.2.3
- Fixed in:
- 3.8.2.3
- Disclosed:
- Feb 27, 2023
CVE-2023-0552 on NVD →
Pie Register <= 3.8.2.2 - Open Redirect
medium
The Pie Register plugin for WordPress is vulnerable to Open Redirect via the 'redirect_to' parameter in versions up to, and including, 3.8.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to redirect users to an external site, if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 3.8.2.2
- Fixed in:
- 3.8.2.3
- Disclosed:
- Feb 6, 2023
CVE-2023-0552 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.8.1.3
unknown
[en] The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
- Affected:
- up to 3.8.1.3
- Fixed in:
- 3.8.1.3
- Disclosed:
- Dec 19, 2022
CVE-2022-4024 on NVD →
Pie Register <= 3.8.1.2 - Missing Authorization to Arbitrary User Deletion
medium
The Pie Register plugin for WordPress is vulnerable to arbitrary user deletion in versions up to, and including, 3.8.1.3. This is due to missing validation and capability checking on code that handles the deletion of users. This makes it possible for unauthenticated attackers to delete arbitrary users.
- CVSS:
- 6.5
- Affected:
- up to 3.8.1.2
- Fixed in:
- 3.8.1.3
- Disclosed:
- Nov 28, 2022
CVE-2022-4024 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.7.1.6
unknown
[en] The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
- Affected:
- up to 3.7.1.6
- Fixed in:
- 3.7.1.6
- Disclosed:
- Nov 8, 2021
CVE-2021-24647 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.7.1.6
unknown
[en] The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.
- Affected:
- up to 3.7.1.6
- Fixed in:
- 3.7.1.6
- Disclosed:
- Nov 8, 2021
CVE-2021-24731 on NVD →
Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments <= 3.7.2.3 - Open Redirect
medium
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 3.7.2.3. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible f...
- CVSS:
- 6.1
- Affected:
- up to 3.7.2.4
- Fixed in:
- 3.7.2.4
- Disclosed:
- Oct 21, 2021
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.7.2.4
unknown
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 3.7.2.3. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible f...
- Affected:
- up to 3.7.2.4
- Fixed in:
- 3.7.2.4
- Disclosed:
- Oct 21, 2021
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.7.2.4
unknown
Open Redirect vulnerability discovered by WPScanTeam in WordPress Pie Register plugin (versions <= 3.7.2.3).
- Affected:
- up to 3.7.2.4
- Fixed in:
- 3.7.2.4
- Disclosed:
- Oct 21, 2021
Pie Register <= 3.7.1.5 - Unauthenticated SQL Injection
critical
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.
- CVSS:
- 9.8
- Affected:
- up to 3.7.1.6
- Fixed in:
- 3.7.1.6
- Disclosed:
- Oct 11, 2021
CVE-2021-24731 on NVD →
Pie Register <= 3.7.1.4 - Authentication Bypass
critical
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.7.1.4. This is due to the plugin not properly validating the identity of a user p...
- CVSS:
- 9.8
- Affected:
- up to 3.7.1.4
- Fixed in:
- 3.7.1.5
- Disclosed:
- Oct 11, 2021
CVE-2025-34077 on NVD →
Pie Register <= 3.7.1.5 - Authentication Bypass
high
The Registration Forms User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
- CVSS:
- 8.1
- Affected:
- up to 3.7.1.6
- Fixed in:
- 3.7.1.6
- Disclosed:
- Oct 11, 2021
CVE-2021-24647 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.7.0.1
unknown
[en] The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.
- Affected:
- up to 3.7.0.1
- Fixed in:
- 3.7.0.1
- Disclosed:
- Apr 22, 2021
CVE-2021-24239 on NVD →
Pie Register – User Registration Forms <= 3.7.0.0 - Reflected Cross-Site Scripting
medium
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.
- CVSS:
- 6.1
- Affected:
- up to 3.7.0.1
- Fixed in:
- 3.7.0.1
- Disclosed:
- Apr 3, 2021
CVE-2021-24239 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.1.2
unknown
[en] The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Aug 27, 2019
CVE-2019-15659 on NVD →
Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments < 3.1.2 - SQL Injection
critical
The Pie Register plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions before 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...
- CVSS:
- 9.8
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jul 3, 2019
CVE-2019-15659 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.0.18
unknown
Unauthenticated Cross-Site Scripting (XSS) vulnerability found by Alvaro J. Gene in WordPress Pie Register plugin (versions <= 3.0.17).
- Affected:
- up to 3.0.18
- Fixed in:
- 3.0.18
- Disclosed:
- Oct 29, 2018
Pie Register < 3.0.18 - Unauthenticated Cross-Site Scripting
high
The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.0.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.1
- Affected:
- up to 3.0.18
- Fixed in:
- 3.0.18
- Disclosed:
- Oct 24, 2018
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.0.18
unknown
The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.0.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 3.0.18
- Fixed in:
- 3.0.18
- Disclosed:
- Oct 24, 2018
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.0.10
unknown
Authenticated Blind SQL Injection (SQLi) vulnerability found by Manuel Garcia Cardenas WordPress Pie Register plugin (versions <= 3.0.9).
- Affected:
- up to 3.0.10
- Fixed in:
- 3.0.10
- Disclosed:
- Jun 20, 2018
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.0.10
unknown
[en] SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
- Affected:
- up to 3.0.10
- Fixed in:
- 3.0.10
- Disclosed:
- Jun 17, 2018
CVE-2018-10969 on NVD →
Pie Register <= 3.0.9 - SQL Injection
critical
Blind SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
- CVSS:
- 9.8
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.10
- Disclosed:
- Jun 12, 2018
CVE-2018-10969 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.19
unknown
[en] Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.
- Affected:
- up to 2.0.19
- Fixed in:
- 2.0.19
- Disclosed:
- Oct 16, 2015
CVE-2015-7377 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.19
unknown
[en] Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin....
- Affected:
- up to 2.0.19
- Fixed in:
- 2.0.19
- Disclosed:
- Oct 16, 2015
CVE-2015-7682 on NVD →
Pie Register – User Registration Forms < 2.0.19 - Authenticated SQL Injection
medium
Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.
- CVSS:
- 6.3
- Affected:
- up to 2.0.19
- Fixed in:
- 2.0.19
- Disclosed:
- Oct 12, 2015
CVE-2015-7682 on NVD →
Pie Register – User Registration Forms < 2.0.19 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.
- CVSS:
- 6.1
- Affected:
- up to 2.0.19
- Fixed in:
- 2.0.19
- Disclosed:
- Oct 12, 2015
CVE-2015-7377 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.16
unknown
This plugin is prone to an privilege escalation vulnerability.
Update the plugin.
- Affected:
- up to 2.0.16
- Fixed in:
- 2.0.16
- Disclosed:
- Jul 4, 2015
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.16
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 2.0.16
- Fixed in:
- 2.0.16
- Disclosed:
- Jul 4, 2015
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.15
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- Jul 4, 2015
Registration Forms – User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations for WordPress 2.0.14 - 2.0.15 - Authentication Bypass
critical
The Registration Forms – User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations plugin for WordPress is vulnerable to authentication bypass in versions 2.0.14 - 2.0.15 . This is due to a lack of validation of user input in a login request to the plugin. This makes it possible for unauthentic...
- CVSS:
- 9.8
- Affected:
- 2.0.14 – 2.0.15
- Fixed in:
- 2.0.16
- Disclosed:
- May 4, 2015
Pie Register 2.0.14-2.0.15 - SQL Injection
critical
The Pie Register plugin for WordPress is vulnerable to SQL Injection via the show_dash_widget’ and ‘invitaion_code’ parameter in versions 2.0.14-2.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
- CVSS:
- 9.8
- Affected:
- 2.0.14 – 2.0.15
- Fixed in:
- 2.0.16
- Disclosed:
- May 4, 2015
Pie Register – User Registration, Profiles & Content Restriction [pie-register] >= 2.0.14 - <= 2.0.15
unknown
The Pie Register plugin for WordPress is vulnerable to SQL Injection via the show_dash_widget’ and ‘invitaion_code’ parameter in versions 2.0.14-2.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
- Affected:
- 2.0.14 – 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- May 4, 2015
Pie Register – User Registration, Profiles & Content Restriction [pie-register] >= 2.0.14 - <= 2.0.15
unknown
The Registration Forms – User Profile, Custom Registration Form, Login Form, Invitation-Based Registrations plugin for WordPress is vulnerable to authentication bypass in versions 2.0.14 - 2.0.15 . This is due to a lack of validation of user input in a login request to the plugin. This makes it possible for unauthentic...
- Affected:
- 2.0.14 – 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- May 4, 2015
Pie Register < 2.0.15 - Cross-Site Scripting
high
The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting via the 'notice' parameter in versions before 2.0.15 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.1
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- Mar 9, 2015
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.15
unknown
The Pie Register plugin for WordPress is vulnerable to Cross-Site Scripting via the 'notice' parameter in versions before 2.0.15 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- Mar 9, 2015
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.14
unknown
[en] The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
- Affected:
- up to 2.0.14
- Fixed in:
- 2.0.14
- Disclosed:
- Jan 23, 2015
CVE-2014-8802 on NVD →
Pie Register <= 2.0.13 - Missing Authorization
high
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
- CVSS:
- 7.3
- Affected:
- up to 2.0.13
- Fixed in:
- 2.0.14
- Disclosed:
- Jan 17, 2015
CVE-2014-8802 on NVD →
Pie Register <= 1.30 - Multiple Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a re...
- CVSS:
- 6.1
- Affected:
- up to 1.30
- Fixed in:
- 1.31
- Disclosed:
- Aug 1, 2014
CVE-2013-4954 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 1.31
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in...
- Affected:
- up to 1.31
- Fixed in:
- 1.31
- Disclosed:
- Jul 29, 2013
CVE-2013-4954 on NVD →
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.7.2.4
unknown
The plugin passes unvalidated user input to the wp_redirect() function, without validating it, leading to an Open redirect issue
- Affected:
- up to 3.7.2.4
- Fixed in:
- 3.7.2.4
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 3.0.18
unknown
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin was affected by an Unauthenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.0.18
- Fixed in:
- 3.0.18
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.16
unknown
User input is not validated correctly when accepting a login request via the Pie Register plugin. It is possible to manipulate posted variables in order to login using an arbitrary User ID (such as 1, for the default Administrative account).
- Affected:
- up to 2.0.16
- Fixed in:
- 2.0.16
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.16
unknown
User input is not validated correctly when accepting an Invitation Code, as such an SQL Injection attack is possible. This attack is triggered when the parameters ‘show_dash_widget’ and ‘invitaion_code’ are provided to any page, by any user (anonymous or otherwise).
- Affected:
- up to 2.0.16
- Fixed in:
- 2.0.16
Pie Register – User Registration, Profiles & Content Restriction [pie-register] < 2.0.15
unknown
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15