Pie Register <3.8.4.10: Predictable Verification Token Vulnerability
CVE-2026-10530 Published on June 22, 2026
Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.