CVE-2022-4309: SUBSCRIBE2 Project SUBSCRIBE2
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing their email via a CSRF attack.
Affected products
- SUBSCRIBE2 Project SUBSCRIBE2: before 10.38 (fixed in 10.38)
Published 2023-01-16. Last modified 2026-06-17.