CVE-2014-8802: Medium severity genetechsolutions pie register premium vulnerability
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8802?
CVE-2014-8802 has a medium severity level due to inadequate access controls in the Pie Register plugin.
How do I fix CVE-2014-8802?
To fix CVE-2014-8802, upgrade the Pie Register plugin to version 2.0.14 or later.
What functions are affected by CVE-2014-8802?
CVE-2014-8802 affects functions in pie-register.php, allowing unauthorized actions like user addition and account activation.
Who can exploit CVE-2014-8802?
Remote attackers can exploit CVE-2014-8802 to manipulate user accounts through crafted CSV uploads.
What is the impact of CVE-2014-8802 on WordPress sites?
CVE-2014-8802 can lead to unauthorized user account creation and activation, compromising site security.