The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-330 |
Mon, 22 Jun 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox. | |
| Title | Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-22T06:00:01.515Z
Reserved: 2026-06-01T11:10:04.525Z
Link: CVE-2026-10530
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T07:30:06Z