HomeWordPress vulnerabilitiesPie Register
Pie Register vulnerabilities
Pie Register has 19 known vulnerabilities in this database. The most recent published record is dated 3 Oct 2026.
- Known vulnerabilities
- 19
- Active installs
- 1,000+
- Latest version
- 3.8.4.14
- Last updated
- 30 Sep 2026
- Most recent
- 3 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-96962 | Low 3.7 | Before 3.8.4.14 | Fixed in 3.8.4.14 | 4 d ago |
| Sensitive data exposure CVE-2026-103345 | Medium 5.3 | Up to 3.8.4.13 | Fixed in a later version (latest 3.8.4.14) | 6 d ago |
| Security weakness CVE-2026-10530 | Medium 5.3 | Before 3.8.4.10 | Fixed in 3.8.4.10 | 22 Jun 2026 |
| Broken access control CVE-2026-3571 | Medium 6.5 | Up to 3.8.4.8 | Fixed in a later version (latest 3.8.4.14) | 4 Apr 2026 |
| Remote code execution CVE-2025-34077 | Critical 10.0 | Not yet published | Check for an update | 9 Jul 2025 |
| Sensitive data exposure CVE-2024-13818 | Medium 5.3 | Up to 3.8.3.9 | Fixed in a later version (latest 3.8.4.14) | 21 Feb 2025 |
| Broken access control CVE-2024-6069 | High 8.8 | Up to 3.8.3.4 | Fixed in a later version (latest 3.8.4.14) | 9 Jul 2024 |
| Authentication bypass CVE-2024-4544 | Critical 9.8 | Up to 1.7.7 | Fixed in a later version (latest 3.8.4.14) | 24 May 2024 |
| Open redirect CVE-2023-0552 | Medium 5.4 | Before 3.8.2.3 | Fixed in 3.8.2.3 | 27 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2022-4024 | Medium 6.5 | Before 3.8.1.3 | Fixed in 3.8.1.3 | 19 Dec 2022 |
| SQL injection CVE-2021-24731 | Critical 9.8 | Before 3.7.1.6 | Fixed in 3.7.1.6 | 8 Nov 2021 |
| Authentication bypass CVE-2021-24647 | High 8.1 | Before 3.7.1.6 | Fixed in 3.7.1.6 | 8 Nov 2021 |
| Cross-site scripting (XSS) CVE-2021-24239 | Medium 6.1 | Before 3.7.0.1 | Fixed in 3.7.0.1 | 22 Apr 2021 |
| SQL injection CVE-2019-15659 | Critical 9.8 | Before 3.1.2 | Fixed in 3.1.2 | 27 Aug 2019 |
| SQL injection CVE-2018-10969 | Critical 9.8 | Before 3.0.10 | Fixed in 3.0.10 | 17 Jun 2018 |
| SQL injection CVE-2015-7682 | Not scored | Up to 2.0.18 | Fixed in a later version (latest 3.8.4.14) | 16 Oct 2015 |
| Cross-site scripting (XSS) CVE-2015-7377 | Not scored | Up to 2.0.18 | Fixed in a later version (latest 3.8.4.14) | 16 Oct 2015 |
| Security weakness CVE-2014-8802 | Not scored | Up to 2.0.13 | Fixed in a later version (latest 3.8.4.14) | 23 Jan 2015 |
| Cross-site scripting (XSS) CVE-2013-4954 | Not scored | Up to 1.30 | Fixed in a later version (latest 3.8.4.14) | 29 Jul 2013 |
Read the published descriptions
- CVE-2026-96962, 3 Oct 2026
- The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code. CVE record
- CVE-2026-103345, 1 Oct 2026
- Insertion of Sensitive Information Into Sent Data vulnerability in Shamim Rajani Pie Register pie-register allows Retrieve Embedded Sensitive Data.This issue affects Pie Register: from n/a through 3.8.4.13. CVE record
- CVE-2026-10530, 22 Jun 2026
- The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox. CVE record
- CVE-2026-3571, 4 Apr 2026
- The Pie Register - User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change registration form status. CVE record
- CVE-2025-34077, 9 Jul 2025
- An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server. CVE record
- CVE-2024-13818, 21 Feb 2025
- The Registration Forms - User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information about users contained in the exposed log files. CVE record
- CVE-2024-6069, 9 Jul 2024
- The Registration Forms - User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pieregister_install_addon function in all versions up to, and including, 3.8.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins. As a result attackers might achieve code execution on the targeted server CVE record
- CVE-2024-4544, 24 May 2024
- The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.7. This is due to insufficient verification on the user being supplied during a social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email. CVE record
- CVE-2023-0552, 27 Feb 2023
- The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability CVE record
- CVE-2022-4024, 19 Dec 2022
- The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts) CVE record
- CVE-2021-24731, 8 Nov 2021
- The Registration Forms - User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection. CVE record
- CVE-2021-24647, 8 Nov 2021
- The Registration Forms - User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username CVE record
- CVE-2021-24239, 22 Apr 2021
- The Pie Register - User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue. CVE record
- CVE-2019-15659, 27 Aug 2019
- The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. CVE record
- CVE-2018-10969, 17 Jun 2018
- SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid. CVE record
- CVE-2015-7682, 16 Oct 2015
- Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php. CVE record
- CVE-2015-7377, 16 Oct 2015
- Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI. CVE record
- CVE-2014-8802, 23 Jan 2015
- The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action. CVE record
- CVE-2013-4954, 29 Jul 2013
- Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a register action. NOTE: some of these details are obtained from third party information. CVE record
What to do if you run Pie Register
If you run Pie Register, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Pie Register vulnerabilities
Free. We email you when a new vulnerability is published for Pie Register, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.