PT-2026-51275 · WordPress · Pie Register

·

CVE-2026-10530

·

Published

2026-06-22

·

Updated

2026-06-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pie Register versions prior to 3.8.4.10
Description The plugin fails to use sufficiently random values when generating account verification tokens. This allows unauthenticated attackers to predict a valid token and activate an account without having access to the associated email inbox.
Recommendations Update to version 3.8.4.10 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-10530

Affected Products

Pie Register