CVE-2025-26940: WordPress Pie Register Premium plugin <= 3.8.3.2 - Path Traversal to Non-Arbitrary File Deletion vulnerability
Path Traversal vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.
Other sources
Path Traversal: '.../...//' vulnerability in NotFound Pie Register Premium pie-register-premium.This issue affects Pie Register Premium: from n/a through <= 3.8.3.2.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Pie Register Premiumto a version that resolves this vulnerability.Fixed in 3.8.3.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26940?
CVE-2025-26940 is rated as a high severity vulnerability due to its potential for path traversal attacks.
How do I fix CVE-2025-26940?
To fix CVE-2025-26940, upgrade to the latest version of Pie Register Premium beyond 3.8.3.2.
What type of vulnerability is CVE-2025-26940?
CVE-2025-26940 is a path traversal vulnerability allowing unauthorized file access.
Which versions of Pie Register Premium are affected by CVE-2025-26940?
CVE-2025-26940 affects Pie Register Premium versions up to and including 3.8.3.2.
What are the consequences of exploiting CVE-2025-26940?
Exploiting CVE-2025-26940 can lead to unauthorized file deletion or access to sensitive data on the server.