← volver
CVE-2022-4024

Pie Register < 3.8.1.3 - Unauthenticated Arbitrary User Deletion

CVSS 6.5 MEDIUMEPSS 0.3%
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →