CVE-2026-96962

low

Description

The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.

References

https://wpscan.com/vulnerability/bf634ddf-277e-46a4-9e5b-7253b3e02979/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91949

Details

Source: Mitre, NVD

Published: 2026-10-03

Updated: 2026-10-03

Risk Information

CVSS v2

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3.7

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Low

EPSS

EPSS: 0.00139