ZeroHour

CVE-2022-3336

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p20
Published
()
Modified
Description

The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack

Vendors
awplife
Products
event monster
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.