CVE-2026-96962 PUBLISHED

Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code

Assigner: WPScan
Reserved: 23.09.2026 Published: 03.10.2026 Updated: 03.10.2026

The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.

Product Status

Vendor Unknown
Product Pie Register
Versions Default: unaffected
  • affected from 0 to 3.8.4.14 (excl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE