What this page helps you verify fast
This hub clusters tracked records for Pie Register – User Registration, Profiles & Content Restriction so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Pie Register – User Registration, Profiles & Content Restriction (`pie-register`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2026-3571, CVE-2026-24577 and CVE-2024-13818, so operators can jump from disclosure to patch validation without scanning the full feed first.
Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.
Review patch cadence, privileged access, XML-RPC exposure, backups, and monitoring controls.
Use ownership, update testing, least privilege, and removal criteria to reduce plugin risk.
Compare scanner coverage for plugin CVEs, version detection, alert noise, and remediation workflow.
Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.
Affected range: Versions up to 3.8.3.2. Fixed version: 3.8.3.3.
Affected range: Versions up to 3.7.1.4. Fixed version: 3.7.1.5.
Affected range: Versions before 3.7.1.6. Fixed version: 3.7.1.6.
Affected range: Versions before 3.1.2. Fixed version: 3.1.2.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
| Tracked CVE | Issue Type | Affected Versions | Fixed Version | CVSS |
|---|---|---|---|---|
|
CVE-2024-27957
Pie Register <= 3.8.3.2 - Unauthenticated Arbitrary File Upload
|
Remote Code Execution | Versions up to 3.8.3.2 | 3.8.3.3 | CVSS 9.8 |
|
CVE-2025-34077
Pie Register <= 3.7.1.4 - Authentication Bypass
|
Vulnerability | Versions up to 3.7.1.4 | 3.7.1.5 | CVSS 9.8 |
|
CVE-2021-24731
Pie Register <= 3.7.1.5 - Unauthenticated SQL Injection
|
SQL Injection | Versions before 3.7.1.6 | 3.7.1.6 | CVSS 9.8 |
|
CVE-2019-15659
Pie Register – User Registration Forms. Invitation based registrations, Custom Login...
|
SQL Injection | Versions before 3.1.2 | 3.1.2 | CVSS 9.8 |
|
CVE-2018-10969
Pie Register <= 3.0.9 - SQL Injection
|
SQL Injection | Versions up to 3.0.9 | 3.0.10 | CVSS 9.8 |
|
CVE-2024-6069
Pie Register - Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber...
|
Vulnerability | Versions up to 3.8.3.4 | 3.8.3.5 | CVSS 8.8 |
|
CVE-2021-24647
Pie Register <= 3.7.1.5 - Authentication Bypass
|
Vulnerability | Versions before 3.7.1.6 | 3.7.1.6 | CVSS 8.1 |
|
CVE-2014-8802
Pie Register <= 2.0.13 - Missing Authorization
|
Vulnerability | Versions up to 2.0.13 | 2.0.14 | CVSS 7.3 |
Pie Register <= 3.8.3.2 - Unauthenticated Arbitrary File Upload
Pie Register <= 3.7.1.4 - Authentication Bypass
Pie Register <= 3.7.1.5 - Unauthenticated SQL Injection
Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments < 3.1.2 - SQL Injection
Pie Register <= 3.0.9 - SQL Injection
Pie Register - Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
Pie Register <= 3.7.1.5 - Authentication Bypass
Pie Register <= 2.0.13 - Missing Authorization
This hub clusters tracked records for Pie Register – User Registration, Profiles & Content Restriction so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main...
The Pie Register plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8.4.8. This makes it possible f...
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Inf...
Sorted by latest disclosure date so newly published issues surface first.
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unau...
The Pie Register plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log...
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pieregister_install...
The Pie Register plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pie_save_registration function in versions up to, and including, 3.8.3.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the...
The Pie Register plugin for WordPress is vulnerable to Open Redirect via the 'redirect_to' parameter in versions up to, and including, 3.8.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to redirect users to an...
The Pie Register plugin for WordPress is vulnerable to arbitrary user deletion in versions up to, and including, 3.8.1.3. This is due to missing validation and capability checking on code that handles the deletion of users. This makes it possible for unauthenticated attackers to...
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments plugin for WordPress is vulnerable to Open Redirects in versions up to, and including, 3.7.2.3. This is due to insufficient validation on the redirect url supplied via the 'redirect...
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.7.1.4. This is due to the plugin not prop...
The Registration Forms User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their us...
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL i...
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.