PatchSiren

Pie Register CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Pie Register CVE published 2026-10-03

CVE-2026-96962

The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code. This vulnerability requires verification of exposure and remediation to prevent potential exploitation. Defenders should assess the impact of unauthor [truncated]