Front End Users <= 3.2.24 - Missing Authorization to Unauthenticated Registered User Deletion

2023-04-07 00:00
Anonymous

Strategic Overview

Status
Patched in 3.2.25
Affected PluginFront End Users
Affected Version<= 3.2.24
CVSS6.5Medium
CVEN/A
View all Front End Users vulnerabilities

Vulnerability Overview

The Front End Users plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions such as Mass_Delete_EWD_FEUP_Users, Delete_All_EWD_FEUP_Users, and Mass_Delete_EWD_FEUP_Fields in versions up to, and including, 3.2.24. This makes it possible for unauthenticated users to perform restricted actions such as deleting users that have registered through the plugin configuration.

Technical Analysis

REMEDIATION: Update to version 3.2.25, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C