First published: Mon Dec 19 2022(Updated: )
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Genetechsolutions Pie Register | <3.8.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.