Executive brief
Pie Register is a WordPress plugin used to manage user registrations, profiles, and content access. A security flaw allows unauthorized individuals to change the status of registration forms without logging in. This could allow attackers to disable new user sign-ups or disrupt the registration process on a website.
Technical details
The Pie Register plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the pie_main() function. This vulnerability exists in all versions up to and including 3.8.4.8. An unauthenticated attacker can exploit this flaw via a network request to modify the status of registration forms. The root cause is categorized as CWE-862 (Missing Authorization). A patch has been identified in the plugin's changeset 3494602.
Affected products
- Genetech Solutions Pie Register – User Registration, Profiles & Content Restriction Up to, and including, 3.8.4.8
Timeline
- 2026-04-03: disclosed
- 2026-04-04: advisory