Vulnerability Description
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Genetechsolutions | Pie Register | < 3.8.1.3 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/a087fb45-6f6c-40ac-b48b-2cbceda86cbeExploitThird Party Advisory
- https://wpscan.com/vulnerability/a087fb45-6f6c-40ac-b48b-2cbceda86cbeExploitThird Party Advisory
FAQ
What is CVE-2022-4024?
CVE-2022-4024 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users...
How severe is CVE-2022-4024?
CVE-2022-4024 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-4024?
Check the references section above for vendor advisories and patch information. Affected products include: Genetechsolutions Pie Register.