Pie Register <= 3.8.1.2 - Missing Authorization to Arbitrary User Deletion
2022-11-28 00:00
cydaveStrategic Overview
StatusPatched in 3.8.1.3
Affected Version
<= 3.8.1.2CVSS6.5Medium
CVE
CVE-2022-4024Vulnerability Overview
The Pie Register plugin for WordPress is vulnerable to arbitrary user deletion in versions up to, and including, 3.8.1.3. This is due to missing validation and capability checking on code that handles the deletion of users. This makes it possible for unauthenticated attackers to delete arbitrary users.
Technical Analysis
REMEDIATION: Update to version 3.8.1.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C