PT-2015-4082 · WordPress · Pie Register

Published

2015-01-23

·

Updated

2015-01-26

·

CVE-2014-8802

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Pie Register plugin versions prior to 2.0.14
Description The issue allows remote attackers to add a user by uploading a crafted CSV file or activate a user account via a verifyit action due to improper access restriction to certain functions in pie-register.php.
Recommendations For versions prior to 2.0.14, update to version 2.0.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the pie-register.php file until a patch is available. Avoid using the verifyit action in the affected plugin until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8802

Affected Products

Pie Register