WordPress Pie Register before 2.0.19 contains a reflected cross-site scripting vulnerability in pie-register/pie-register.php which allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URL.
View the template here CVE-2015-7377.yaml
References:
https://wpvulndb.com/vulnerabilities/8212