CVE-2022-4024: Pie Register < 3.8.1.3 - Unauthenticated Arbitrary User Deletion
Published Dec 19, 2022
·Updated
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
Affected Software
1 affected component
Genetechsolutions Pie Register Wordpress<3.8.1.3
Event History
Dec 19, 2022
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-4024?
CVE-2022-4024 is classified as a high severity vulnerability due to its potential for unauthenticated user deletion.
2
How do I fix CVE-2022-4024?
To fix CVE-2022-4024, upgrade the Registration Forms WordPress plugin to version 3.8.1.3 or later.
3
What does CVE-2022-4024 allow attackers to do?
CVE-2022-4024 allows unauthenticated attackers to delete arbitrary users and their posts from the WordPress site.
4
Which versions of the Registration Forms plugin are affected by CVE-2022-4024?
CVE-2022-4024 affects all versions of the Registration Forms WordPress plugin before 3.8.1.3.
5
Is authentication required to exploit CVE-2022-4024?
No, CVE-2022-4024 can be exploited without authentication.