CVE-2026-96962: Unknown Pie Register

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.

Affected products

  • Unknown Pie Register: before 3.8.4.14 (fixed in 3.8.4.14)

Published 2026-10-03. Last modified 2026-10-06.