Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-4024


The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)


Published

2022-12-19T14:15:11.760

Last Modified

2025-04-17T15:15:53.687

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-352
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application genetechsolutions pie_register < 3.8.1.3 Yes

References