CVE-2021-24647
HIGH EXPLOITED NUCLEIGenetechsolutions Pie Register < 3.7.1.6 - Authentication Bypass
Title source: ruleDescription
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
Exploits (1)
nomisec
WORKING POC
1 stars
by RandomRobbieBF · remote
https://github.com/RandomRobbieBF/CVE-2021-24647
Nuclei Templates (1)
Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login
HIGHVERIFIEDby DhiyaneshDK
Scores
CVSS v3
8.1
EPSS
0.8503
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2021-10-11
CWE
CWE-287
Status
published
Products (1)
genetechsolutions/pie_register
< 3.7.1.6
Published
Nov 08, 2021
Tracked Since
Feb 18, 2026