CVE-2022-4266
26.12.2022, 13:15
The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete non admin users by knowing their email via a CSRF attackEnginsight
Vendor | Product | Version |
---|---|---|
speakdigital | bulk_delete_users_by_email | 𝑥 ≤ 1.2 |
𝑥
= Vulnerable software versions