CVE-2026-96962: Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code
The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pie Registerto a version that resolves this vulnerability.Fixed in 3.8.4.14
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated visitor can access the affected report if they know a valid invitation code. No account or administrative access is required.
What information can be exposed?
The report can disclose the username and email address of every user who registered using the known invitation code.
Which installations are affected?
Pie Register versions before 3.8.4.14 are affected. The issue is reachable without authentication where a valid invitation code is known.