CVE-2014-8802
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
23/01/2015
Last modified:
12/04/2025
Description
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:genetechsolutions:pie_register:*:*:*:*:*:wordpress:*:* | 2.0.13 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/62351
- http://security.szurek.pl/pie-register-2013-privilege-escalation.html
- https://wordpress.org/plugins/pie-register/changelog/
- http://secunia.com/advisories/62351
- http://security.szurek.pl/pie-register-2013-privilege-escalation.html
- https://wordpress.org/plugins/pie-register/changelog/