Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2022-4024
Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
0
Attacker Value
Unknown
CVE-2021-24647
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
0
Attacker Value
Unknown
CVE-2021-24731
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.
0
Attacker Value
Unknown
CVE-2021-24239
Disclosure Date: April 22, 2021 (last updated February 22, 2025)
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2019-15659
Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
0
Attacker Value
Unknown
CVE-2019-1010207
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the attacker can steal his/her account. The fixed version is: 3.0.16.
0
Attacker Value
Unknown
CVE-2018-10969
Disclosure Date: June 17, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
0
Attacker Value
Unknown
CVE-2015-7682
Disclosure Date: October 16, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2015-7377
Disclosure Date: October 16, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.
0
Attacker Value
Unknown
CVE-2014-8802
Disclosure Date: January 23, 2015 (last updated October 05, 2023)
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
0