← Vulnerability feed

Vulnerability record · CVE-2022-4024 · published 19 December 2022

CVE-2022-4024: Genetechsolutions pie register cross-site request forgery vulnerability

Genetechsolutions · Pie Register

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

6.5 CVSS 3.1 Medium EPSS 0.33% · top 75.8% CWE-352 · Cross-site request forgeryCWE-862 · Missing authorization
6.5CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-4024 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27957Genetechsolutions pie register unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.EPSS 0.61%9.8CVE-2021-24731Genetechsolutions pie register sql injection vulnerabilityThe Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does …EPSS 6.4%9.8CVE-2019-15659Genetechsolutions pie register sql injection vulnerabilityThe pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.EPSS 1.9%9.8CVE-2018-10969Genetechsolutions pie register sql injection vulnerabilitySQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the …EPSS 5.3%8.1CVE-2021-24647Genetechsolutions pie register improper authentication vulnerabilityThe Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a…EPSS 9.8%7.5CVE-2024-13818Genetechsolutions pie register sensitive information in log file vulnerabilityThe Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for…EPSS 0.51%6.5CVE-2015-7682Genetechsolutions pie register sql injection vulnerabilityMultiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administr…EPSS 1.4%6.1CVE-2021-24239Genetechsolutions pie register cross-site scripting vulnerabilityThe Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2022-4024), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.