CVE-2026-10530 PUBLISHED

Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token

Assigner: WPScan
Reserved: 01.06.2026 Published: 22.06.2026 Updated: 22.06.2026

The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.

Product Status

Vendor Unknown
Product Pie Register
Versions Default: unaffected
  • affected from 0 to 3.8.4.10 (excl.)

Credits

  • Haitam Lazaar finder
  • WPScan coordinator

References

Problem Types

  • CWE-326 Inadequate Encryption Strength CWE