← Vulnerability feed

Vulnerability record · CVE-2014-8802 · published 23 January 2015

CVE-2014-8802: Genetechsolutions pie register permissions and access controls vulnerability

Genetechsolutions · Pie Register

The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

5.0 CVSS 2.0 Medium EPSS 7.4% · top 5.8% CWE-264 · Permissions and access controls
5.0CVSS 2.0 base score
7.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-8802 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27957Genetechsolutions pie register unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.EPSS 0.61%9.8CVE-2021-24731Genetechsolutions pie register sql injection vulnerabilityThe Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does …EPSS 6.4%9.8CVE-2019-15659Genetechsolutions pie register sql injection vulnerabilityThe pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.EPSS 1.9%9.8CVE-2018-10969Genetechsolutions pie register sql injection vulnerabilitySQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the …EPSS 5.3%8.1CVE-2021-24647Genetechsolutions pie register improper authentication vulnerabilityThe Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a…EPSS 9.8%7.5CVE-2024-13818Genetechsolutions pie register sensitive information in log file vulnerabilityThe Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for…EPSS 0.51%6.5CVE-2022-4024Genetechsolutions pie register cross-site request forgery vulnerabilityThe Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing …EPSS 0.33%6.5CVE-2015-7682Genetechsolutions pie register sql injection vulnerabilityMultiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administr…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2014-8802), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.