PT-2022-25302 · WordPress · Registration Forms
Cydave
·
Published
2022-12-19
·
Updated
2023-06-27
·
CVE-2022-4024
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Registration Forms WordPress plugin versions prior to 3.8.1.3
Description
The issue allows unauthenticated attackers to delete arbitrary users, along with their posts, due to a lack of authorisation and CSRF protection when deleting users via an init action handler.
Recommendations
For versions prior to 3.8.1.3, update to version 3.8.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the init action handler to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Registration Forms