Vulnerabilities
Vulnerable Software
Genetechsolutions:  >> Pie Register  Security Vulnerabilities
Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.
CVSS Score
6.5
EPSS Score
0.004
Published
2015-10-16
Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.
CVSS Score
4.3
EPSS Score
0.07
Published
2015-10-16
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
CVSS Score
5.0
EPSS Score
0.08
Published
2015-01-23


Contact Us

Shodan ® - All rights reserved