cbcvebase.

Genetechsolutions Pie Register vulnerabilities

13 known vulnerabilities affecting genetechsolutions/pie_register.

Total CVEs
13
CISA KEV
0
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH2MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2021-24647P1HIGHCVSS 8.1ExploitedPoCfixed in 3.7.1.62021-11-08
CVE-2021-24647 [HIGH] CWE-287 CVE-2021-24647: The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invit The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
nvd
CVE-2023-0552P2MEDIUMCVSS 5.4ExploitedPoCfixed in 3.8.2.32023-02-27
CVE-2023-0552 [MEDIUM] CWE-601 CVE-2023-0552: The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection UR The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability
nvd
CVE-2021-24731P2CRITICALCVSS 9.8PoCfixed in 3.7.1.62021-11-08
CVE-2021-24731 [CRITICAL] CWE-89 CVE-2021-24731: The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invit The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.
nvd
CVE-2018-10969P2CRITICALCVSS 9.8PoCfixed in 3.0.102018-06-17
CVE-2018-10969 [CRITICAL] CWE-89 CVE-2018-10969: SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote att SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
nvd
CVE-2014-8802P3MEDIUMCVSS 5.0PoC≤ 2.0.132015-01-23
CVE-2014-8802 [MEDIUM] CWE-264 CVE-2014-8802: The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain fun The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
nvd
CVE-2024-27957P3CRITICALCVSS 9.8fixed in 3.8.3.32024-03-17
CVE-2024-27957 [CRITICAL] CWE-434 CVE-2024-27957: Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.
nvd
CVE-2021-24239P3MEDIUMCVSS 6.1PoCfixed in 3.7.0.12021-04-22
CVE-2021-24239 [MEDIUM] CWE-79 CVE-2021-24239: The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments W The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.
nvd
CVE-2019-15659P3CRITICALCVSS 9.8fixed in 3.1.22019-08-27
CVE-2019-15659 [CRITICAL] CVE-2019-15659: The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-201 The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
nvd
CVE-2024-13818P3HIGHCVSS 7.5≤ 3.8.3.92025-02-21
CVE-2024-13818 [HIGH] CWE-532 CVE-2024-13818: The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Pro The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log files. This makes it possible for unauthenticated attackers to view pote
nvd
CVE-2015-7377P4MEDIUMCVSS 4.3PoC≤ 2.0.182015-10-16
CVE-2015-7377 [MEDIUM] CWE-79 CVE-2015-7377: Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.
nvd
CVE-2015-7682P3MEDIUMCVSS 6.5≤ 2.0.182015-10-16
CVE-2015-7682 [MEDIUM] CWE-89 CVE-2015-7682: Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin b Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.
nvd
CVE-2022-4024P4MEDIUMCVSS 6.5fixed in 3.8.1.32022-12-19
CVE-2022-4024 [MEDIUM] CWE-352 CVE-2022-4024: The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when del The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
nvd
CVE-2019-1010207P4MEDIUMCVSS 6.1v3.0.15v3.0.15 [fixed: 3.0.16]2019-07-23
CVE-2019-1010207 [MEDIUM] CWE-79 CVE-2019-1010207: Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Ste Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the attacker can steal his/her account. The fixed version is: 3.0.16.
nvd
Genetechsolutions Pie Register vulnerabilities | cvebase