VYPR

Pie Register

by Genetechsolutions

Source repositories

CVEs (14)

  • CVE-2018-10969CriJun 17, 2018
    risk 0.67cvss 9.8epss 0.05

    SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.

  • CVE-2024-27957CriMar 17, 2024
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.

  • CVE-2021-24731CriNov 8, 2021
    risk 0.64cvss 9.8epss 0.07

    The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an…

  • CVE-2019-15659CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.

  • CVE-2021-24647HigNov 8, 2021
    risk 0.53cvss 8.1epss 0.10

    The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing…

  • CVE-2022-4024MedDec 19, 2022
    risk 0.42cvss 6.5epss 0.00

    The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

  • CVE-2021-24239MedApr 22, 2021
    risk 0.40cvss 6.1epss 0.02

    The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting…

  • CVE-2019-1010207MedJul 23, 2019
    risk 0.40cvss 6.1epss 0.02

    Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the…

  • CVE-2023-0552MedFeb 27, 2023
    risk 0.37cvss 5.4epss 0.24

    The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

  • CVE-2024-13818MedFeb 21, 2025
    risk 0.34cvss 5.3epss 0.00

    The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed…

  • CVE-2015-7682Oct 16, 2015
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the…

  • CVE-2015-7377Oct 16, 2015
    risk 0.00cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.

  • CVE-2014-8802Jan 23, 2015
    risk 0.00cvss epss 0.08

    The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

  • CVE-2013-4954Jul 29, 2013
    risk 0.00cvss epss 0.06

    Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the…