Vendorsgenetechsolutionspie_registerany version
Vulnerabilities

genetechsolutions Pie Register for WordPress any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2024-27957
WordPress Pie Register plugin <= 3.8.3.1 - Unauthenticated Arbitrary File Upload vulnerability
Published 2024-03-17 · Modified
10.0EPSS 0.006
CVE-2021-24731
Pie Register < 3.7.1.6 - Unauthenticated SQL Injection
Published 2021-11-08 · Modified
9.8EPSS 0.064
CVE-2018-10969
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
Published 2018-06-17 · Modified
9.81 PoCEPSS 0.053
CVE-2019-15659
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
Published 2019-08-27 · Modified
9.8EPSS 0.019
CVE-2021-24647
Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login
Published 2021-11-08 · Modified
8.1EPSS 0.098
CVE-2024-13818
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction <= 3.8.4 - Sensitive Information Exposure via Log Files
Published 2025-02-21 · Modified
7.5EPSS 0.005
CVE-2015-7682
Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.
Published 2015-10-16 · Modified
6.5EPSS 0.014
CVE-2022-4024
Pie Register < 3.8.1.3 - Unauthenticated Arbitrary User Deletion
Published 2022-12-19 · Modified
6.5EPSS 0.003
CVE-2021-24239
Pie Register < 3.7.0.1 - Reflected Cross-Site Scripting (XSS)
Published 2021-04-22 · Modified
6.1EPSS 0.016
CVE-2023-0552
Pie Register < 3.8.2.3 - Open Redirect
Published 2023-02-27 · Modified
5.4EPSS 0.243
CVE-2014-8802
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
Published 2015-01-23 · Modified
5.01 PoCEPSS 0.074
CVE-2015-7377
Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.
Published 2015-10-16 · Modified
4.3EPSS 0.044