VulnerabilityModified
CVE-2022-1603
The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list
MEDIUM 4.3EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- webfwd/mail subscribe list
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/0e12ba6f-a86f-4cc6-9013-8a15586098d0Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/0e12ba6f-a86f-4cc6-9013-8a15586098d0Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.