CVE-2026-10530: Unknown Pie Register
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.
Affected products
- Unknown Pie Register: before 3.8.4.10 (fixed in 3.8.4.10)
Published 2026-06-22. Last modified 2026-06-22.