WordPress Plugin Vulnerabilities

Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code

Description

The plugin does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.

Proof of Concept

Affects Plugins

Fixed in 3.8.4.14

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Usama Arshad
Submitter
Usama Arshad
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-10-01 (about 2 days ago)
Added
2026-10-01 (about 1 day ago)
Last Updated
2026-10-01 (about 1 day ago)

Other