---
id: CVE-2026-96962
title: >-
  The Pie Register  WordPress plugin before 3.8.4.14 does not restrict access to
  an invitation-code report, allowing unauthenticated visitors who know a valid
  invitation code to obtain the username and email address of every user who
  regis…
summary: >-
  The Pie Register  WordPress plugin before 3.8.4.14 does not restrict access to
  an invitation-code report, allowing unauthenticated visitors who know a valid
  invitation code to obtain the username and email address of every user who
  regis…
severity: none
cwe:
  - CWE-200
product: Pie Register
affected:
  - pie_register < 3.8.4.14
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:48.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96962'
references:
  - url: 'https://wpscan.com/vulnerability/bf634ddf-277e-46a4-9e5b-7253b3e02979/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.570Z'
---

## Overview

The Pie Register  WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid invitation code to obtain the username and email address of every user who registered with that code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
