Lucene search

K
cvelistWPScanCVELIST:CVE-2022-4024
HistoryDec 19, 2022 - 1:41 p.m.

CVE-2022-4024 Pie Register < 3.8.1.3 - Unauthenticated Arbitrary User Deletion

2022-12-1913:41:40
WPScan
www.cve.org
2
cve-2022-4024
pie register
unauthenticated
user deletion
wordpress
csrf
authorization
arbitrary users
init action
attackers
posts

EPSS

0.001

Percentile

40.2%

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Registration Forms",
    "collectionURL": "https://wordpress.org/plugins",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "3.8.1.3"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

EPSS

0.001

Percentile

40.2%

Related for CVELIST:CVE-2022-4024