CVE-2025-26948: WordPress Pie Register Premium plugin <= 3.8.3.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in NotFound Pie Register Premium pie-register-premium.This issue affects Pie Register Premium: from n/a through <= 3.8.3.2.
Other sources
Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Pie Register Premiumto a version that resolves this vulnerability.Fixed in 3.8.3.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26948?
The severity of CVE-2025-26948 is classified as high due to the missing authorization vulnerability.
How do I fix CVE-2025-26948?
To fix CVE-2025-26948, update the Pie Register Premium Plugin to version 3.8.3.3 or later.
What systems are affected by CVE-2025-26948?
CVE-2025-26948 affects the Pie Register Premium Plugin versions up to and including 3.8.3.2.
What type of vulnerability is CVE-2025-26948?
CVE-2025-26948 is categorized as a missing authorization vulnerability affecting the Pie Register Premium Plugin.
Can CVE-2025-26948 lead to account takeover?
Yes, the missing authorization in CVE-2025-26948 can potentially lead to unauthorized access and account takeover.