Review
Pie Register
CVE published 2026-10-03
CVE-2026-96962
The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code. This vulnerability requires verification of exposure and remediation to prevent potential exploitation. Defenders should assess the impact of unauthor [truncated]