CVE-2025-34077: WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting socialsite=true and manipulating the useridsocialsite parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34077?
CVE-2025-34077 has a critical severity rating due to its potential to allow unauthorized access and user impersonation.
How do I fix CVE-2025-34077?
To fix CVE-2025-34077, update the WordPress Pie Register plugin to version 3.7.1.5 or later.
What types of attacks can exploit CVE-2025-34077?
CVE-2025-34077 can be exploited through crafted POST requests to impersonate users without authentication.
What systems are affected by CVE-2025-34077?
CVE-2025-34077 affects the WordPress Pie Register plugin versions up to 3.7.1.4.
Who can be impacted by an exploit of CVE-2025-34077?
Unauthenticated attackers can impact any site using the vulnerable WordPress Pie Register plugin.