Junglewise Threat Intelligence

CVE-2026-3571: Genetech Pie Register unauthorized data modification in pie_main

CVE-2026-3571 · Severity: medium · CVSS 6.5 · Published 2026-04-04

Executive brief

Pie Register is a WordPress plugin used to manage user registrations, profiles, and content access. A security flaw allows unauthorized individuals to change the status of registration forms without logging in. This could allow attackers to disable new user sign-ups or disrupt the registration process on a website.

Technical details

The Pie Register plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the pie_main() function. This vulnerability exists in all versions up to and including 3.8.4.8. An unauthenticated attacker can exploit this flaw via a network request to modify the status of registration forms. The root cause is categorized as CWE-862 (Missing Authorization). A patch has been identified in the plugin's changeset 3494602.

Affected products

  • Genetech Solutions Pie Register – User Registration, Profiles & Content Restriction Up to, and including, 3.8.4.8

Timeline

  • 2026-04-03: disclosed
  • 2026-04-04: advisory

References