PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3571 genetechproducts CVE debrief

The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change registration form status. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of the Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress should be aware of this vulnerability and take immediate action to update to a patched version. The vulnerability allows attackers to change registration form status, which could lead to unauthorized access or modifications to user data.

Vendor
genetechproducts
Product
Pie Register – User Registration, Profiles & Content Restriction
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-04
Original CVE updated
2026-07-24
Advisory published
2026-04-04
Advisory updated
2026-07-24

Who should care

Users of the Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress should be aware of this vulnerability and take immediate action to update to a patched version. Operators of WordPress deployments with the affected plugin installed should review their exposure and implement compensating controls if necessary. Vulnerability management and security teams should prioritize patching and monitoring for suspicious activity.

Technical summary

The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change registration form status. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Affected product context indicates that the vulnerability is present in all versions up to, and including, 3.8.4.8. Defensive impact is that attackers can change registration form status, which could lead to unauthorized access or modifications to user data.

Defensive priority

Medium priority

Recommended defensive actions

  • Update to a patched version of the Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress
  • Monitor for suspicious activity on the registration form
  • Implement additional security measures to prevent unauthorized access
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-04-04T02:15:59.310Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The source details are limited, and defenders should verify the affected scope and severity with the vendor. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Evidence is limited to CVE and NVD information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-3571 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-3571

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-3571 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3571

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.