First published: Mon Dec 19 2022(Updated: )
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Genetechsolutions Pie Register Premium | <3.8.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4024 is classified as a high severity vulnerability due to its potential for unauthenticated user deletion.
To fix CVE-2022-4024, upgrade the Registration Forms WordPress plugin to version 3.8.1.3 or later.
CVE-2022-4024 allows unauthenticated attackers to delete arbitrary users and their posts from the WordPress site.
CVE-2022-4024 affects all versions of the Registration Forms WordPress plugin before 3.8.1.3.
No, CVE-2022-4024 can be exploited without authentication.