PT-2025-28828 · WordPress · Wordpress Pie Register
Lotfi13-Dz
·
Published
2025-07-09
·
Updated
2025-07-28
·
CVE-2025-34077
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
WordPress Pie Register plugin versions ≤ 3.7.1.4
Description:
An authentication bypass issue exists that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the "login endpoint". By setting
social site = true and manipulating the user id social site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.Recommendations:
For WordPress Pie Register plugin versions ≤ 3.7.1.4, update to a version greater than 3.7.1.4 to resolve the issue. As a temporary workaround, consider disabling the plugin upload functionality to minimize the risk of exploitation. Restrict access to the login endpoint to prevent unauthorized access.
Exploit
Fix
RCE
Missing Authentication
Unrestricted File Upload
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wordpress Pie Register