ZeroHour

CVE-2022-4024

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p27
Published
()
Modified
Description

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

Vendors
genetechsolutions
Products
pie register
Ecosystems
WordPress
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.