Missing Authorization Vulnerability in NotFound Pie Register Premium
CVE-2025-26948
4.3MEDIUM
Key Information:
- Vendor
- Notfound
- Status
- Pie Register Premium
- Vendor
- CVE Published:
- 25 February 2025
Summary
A missing authorization vulnerability exists in the NotFound Pie Register Premium plugin, affecting versions up to 3.8.3.2. This flaw could allow unauthorized users to access restricted areas, potentially compromising user data and site security. It’s crucial for website owners to update to secure versions to mitigate risks associated with this vulnerability.
Affected Version(s)
Pie Register Premium <= 3.8.3.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack)