PoC Index

CVE-2022-4024

MEDIUM 6.5EPSS 0.3%

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
0.33% chance of exploitation in the next 30 days, 26th percentile
Published
2022-12-19
Updated
2025-04-17

Proof-of-concept exploits (1)

References

Related