CVE-2026-96962: Unknown Pie Register
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.
Affected products
- Unknown Pie Register: before 3.8.4.14 (fixed in 3.8.4.14)
Published 2026-10-03. Last modified 2026-10-06.