CVE-2026-96962 Overview
CVE-2026-96962 is an information disclosure vulnerability in the Pie Register WordPress plugin versions prior to 3.8.4.14. The plugin fails to restrict access to an invitation-code report endpoint. Unauthenticated visitors who know a valid invitation code can retrieve the username and email address of every user who registered with that code. The flaw is classified under CWE-200: Exposure of Sensitive Information to an Unauthorized Actor. Exploitation requires knowledge of a valid invitation code, which raises attack complexity but does not require authentication or user interaction.
Critical Impact
Unauthenticated disclosure of registered usernames and email addresses tied to any known invitation code, enabling targeted phishing and credential-stuffing campaigns.
Affected Products
- Pie Register WordPress plugin versions before 3.8.4.14
- WordPress sites using Pie Register invitation-code based registration
- Any site exposing the plugin's invitation-code report endpoint to unauthenticated users
Discovery Timeline
- 2026-10-03 - CVE-2026-96962 published to the National Vulnerability Database (NVD)
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-96962
Vulnerability Analysis
The Pie Register plugin provides invitation-code based user registration for WordPress. It exposes a report view that lists users who signed up with a given invitation code. The plugin does not enforce an authentication or capability check before returning this report. An attacker who supplies a valid invitation-code value receives back the usernames and email addresses of every account registered with that code.
The disclosed data is limited in scope but directly identifies real users on the target WordPress site. Attackers can combine the harvested usernames and email addresses with password-spraying, credential-stuffing, or targeted phishing attacks against the WordPress login endpoint. Email enumeration also supports social engineering against the broader organization.
Root Cause
The root cause is a missing authorization check [CWE-200] on the invitation-code report handler. The plugin treats possession of a valid invitation code as sufficient authority to view the registration list, rather than restricting the report to administrators or the inviting user. No capability check such as current_user_can('manage_options') guards the handler.
Attack Vector
The attack is network-based and does not require authentication or user interaction. An attacker must know or guess a valid invitation code to retrieve data. Invitation codes may be shared in emails, forums, or chat channels, and can leak through screenshots, archived messages, or referrer logs. Once a valid code is known, the attacker issues a direct request to the report endpoint and parses the returned user list.
No verified public exploit code is available at this time. Technical details are documented in the WPScan Vulnerability Report.
Detection Methods for CVE-2026-96962
Indicators of Compromise
- Unauthenticated HTTP requests to Pie Register report endpoints containing an invitation_code or equivalent parameter
- Repeated requests from a single source iterating over candidate invitation-code values
- Anomalous outbound email traffic to addresses that match recently registered users on the WordPress site
Detection Strategies
- Review web server access logs for GET or POST requests referencing Pie Register report URLs by unauthenticated sessions
- Correlate spikes in requests to registration-related plugin endpoints with subsequent login failures or phishing reports
- Alert on requests to Pie Register admin or report paths that return HTTP 200 without an authenticated WordPress session cookie
Monitoring Recommendations
- Enable verbose logging on the WordPress site, including request parameters and response sizes for plugin endpoints
- Monitor the installed Pie Register version against 3.8.4.14 across all managed WordPress properties
- Track outbound notifications and audit any mass-email or phishing reports from users whose addresses were held in invitation-code registrations
How to Mitigate CVE-2026-96962
Immediate Actions Required
- Upgrade the Pie Register plugin to version 3.8.4.14 or later on every affected WordPress site
- Rotate or invalidate active invitation codes issued before the upgrade to limit the usefulness of previously leaked codes
- Notify users registered through invitation codes that their email address may have been exposed and advise phishing vigilance
Patch Information
The vendor addressed the issue in Pie Register version 3.8.4.14 by restricting access to the invitation-code report. Review the WPScan Vulnerability Report for advisory details and update guidance.
Workarounds
- Restrict access to the plugin's report endpoint at the web server or Web Application Firewall (WAF) layer until the patch is applied
- Temporarily disable invitation-code registration and remove existing codes if an immediate upgrade is not possible
- Require authentication in front of the WordPress admin area using HTTP basic auth or an IP allowlist for administrative paths
# Example WAF rule concept: block unauthenticated access to the Pie Register report path
# Replace the path with the exact endpoint used by your installation.
location ~* /wp-admin/admin\.php {
if ($arg_page ~* "pie-?register") {
# Require a valid WordPress logged_in cookie
if ($http_cookie !~* "wordpress_logged_in_") {
return 403;
}
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.