Missing Authorization Vulnerability in NotFound Pie Register Premium
CVE-2025-26948

4.3MEDIUM

Key Information:

Vendor
Notfound
Status
Pie Register Premium
Vendor
CVE Published:
25 February 2025

Summary

A missing authorization vulnerability exists in the NotFound Pie Register Premium plugin, affecting versions up to 3.8.3.2. This flaw could allow unauthorized users to access restricted areas, potentially compromising user data and site security. It’s crucial for website owners to update to secure versions to mitigate risks associated with this vulnerability.

Affected Version(s)

Pie Register Premium <= 3.8.3.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.