Beta

Report

Pie Register < 3.8.1.3 is vulnerable to Unauthenticated Arbitrary User Deletion vulnerability

Unauthenticated
Published
2023-02-27

The Pie Register plugin for WordPress is vulnerable to arbitrary user deletion in versions up to, and including, 3.8.1.3. This is due to missing validation and capability checking on code that handles the deletion of users. This makes it possible for unauthenticated attackers to delete arbitrary users.

CVSS

Score:8.2

Severity:High

Version:< 3.8.1.3

There is a patch available in v3.8.1.3 and we strongly recommend you update to this version as soon as possible.