← Vulnerability feed

Vulnerability record · CVE-2021-24647 · published 8 November 2021

CVE-2021-24647: Genetechsolutions pie register improper authentication vulnerability

Genetechsolutions · Pie Register

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

8.1 CVSS 3.1 High EPSS 9.8% · top 4.6% CWE-287 · Improper authentication
8.1CVSS 3.1 base score, v2 6.8
9.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24647 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27957Genetechsolutions pie register unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.EPSS 0.61%9.8CVE-2021-24731Genetechsolutions pie register sql injection vulnerabilityThe Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does …EPSS 6.4%9.8CVE-2019-15659Genetechsolutions pie register sql injection vulnerabilityThe pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.EPSS 1.9%9.8CVE-2018-10969Genetechsolutions pie register sql injection vulnerabilitySQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the …EPSS 5.3%7.5CVE-2024-13818Genetechsolutions pie register sensitive information in log file vulnerabilityThe Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for…EPSS 0.51%6.5CVE-2022-4024Genetechsolutions pie register cross-site request forgery vulnerabilityThe Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing …EPSS 0.33%6.5CVE-2015-7682Genetechsolutions pie register sql injection vulnerabilityMultiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administr…EPSS 1.4%6.1CVE-2021-24239Genetechsolutions pie register cross-site scripting vulnerabilityThe Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2021-24647), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.