Impact
The Pie Register WordPress plugin versions prior to 3.8.4.14 exposes a report endpoint that should be protected by authentication. An attacker who knows a valid invitation code can query this endpoint without logging in and receive the usernames and email addresses of every user who registered with that code. This vulnerability allows an unauthenticated user to obtain potentially sensitive personal information, violating confidentiality and potentially enabling targeted phishing or social engineering attacks. The weakness is an information disclosure flaw caused by improper access control on a sensitive endpoint.
Affected Systems
Any WordPress site that has the Pie Register plugin installed with a version older than 3.8.4.14 is affected. The plugin is listed under the vendor "Unknown:Pie Register" and the vulnerability applies to all instances where the invitation-code report is enabled.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating that it has not yet been publicly exploited in the wild or may not be widely known to exploit. However, the attack vector is straightforward: an attacker only needs to know a valid invitation code, which could be leaked or discovered through other means. The absence of authentication on the endpoint makes exploitation trivial once the code is known. Because of the potential for widespread disclosure of user credentials, the confidentiality impact can be high. The lack of known exploits or risk mitigation measures suggests a moderate to high likelihood of exploitation if the code is compromised. The CVSS score is not provided in the input, so the exact severity is unknown, but the description implies a significant information exposure.
OpenCVE Enrichment