Description
The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.
Published: 2026-10-03
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The Pie Register WordPress plugin versions prior to 3.8.4.14 exposes a report endpoint that should be protected by authentication. An attacker who knows a valid invitation code can query this endpoint without logging in and receive the usernames and email addresses of every user who registered with that code. This vulnerability allows an unauthenticated user to obtain potentially sensitive personal information, violating confidentiality and potentially enabling targeted phishing or social engineering attacks. The weakness is an information disclosure flaw caused by improper access control on a sensitive endpoint.

Affected Systems

Any WordPress site that has the Pie Register plugin installed with a version older than 3.8.4.14 is affected. The plugin is listed under the vendor "Unknown:Pie Register" and the vulnerability applies to all instances where the invitation-code report is enabled.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating that it has not yet been publicly exploited in the wild or may not be widely known to exploit. However, the attack vector is straightforward: an attacker only needs to know a valid invitation code, which could be leaked or discovered through other means. The absence of authentication on the endpoint makes exploitation trivial once the code is known. Because of the potential for widespread disclosure of user credentials, the confidentiality impact can be high. The lack of known exploits or risk mitigation measures suggests a moderate to high likelihood of exploitation if the code is compromised. The CVSS score is not provided in the input, so the exact severity is unknown, but the description implies a significant information exposure.

Generated by OpenCVE AI on October 3, 2026 at 07:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Pie Register plugin to version 3.8.4.14 or later, which secures the invitation-code report endpoint with proper authentication.
  • If an immediate upgrade is not possible, implement a temporary access restriction by disabling the invitation-code report or limiting it to administrator roles through plugin settings or custom code.
  • Apply site‑wide monitoring to detect unexpected access to the invitation-code report endpoint and investigate any anomalies promptly.

Generated by OpenCVE AI on October 3, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.
Title Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:20.776Z

Reserved: 2026-09-23T20:36:59.872Z

Link: CVE-2026-96962

cve-icon Vulnrichment

Updated: 2026-10-03T14:59:40.440Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:48.670

Modified: 2026-10-03T16:16:48.203

Link: CVE-2026-96962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T07:30:20Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-285

    Improper Authorization