5
CVSSv2

CVE-2014-8802

Published: 23/01/2015 Updated: 26/01/2015
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Pie Register plugin prior to 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote malicious users to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

Vulnerable Product Search on Vulmon Subscribe to Product

genetechsolutions pie register

Exploits

# Exploit Title: Pie Register 2013 Privilege escalation # Date: 16-10-2014 # Software Link: wordpressorg/plugins/pie-register/ # Exploit Author: Kacper Szurek # Contact: twittercom/KacperSzurek # Website: securityszurekpl/ # CVE: CVE-2014-8802 # Category: webapps 1 Description Anyone can import CSV file Pie Registe ...