CVE-2022-4309: SUBSCRIBE2 Project SUBSCRIBE2

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing their email via a CSRF attack.

Affected products

Published 2023-01-16. Last modified 2026-06-17.