Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login
60Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 9.7%
from disclosure to weapon584 days
Published on NVDNov 8
1st PoC+584d
VulnCheckOct 11
exploitation probability
9.7%top 5% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
Affected products
Unknown · Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codespublic PoCs found — 1
vulncheckvulncheck.com/xdb/66668f877c28unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.