4.3
CVSSv3

CVE-2022-1603

Published: 20/06/2022 Updated: 01/07/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Mail Subscribe List WordPress plugin prior to 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow malicious users to make a logged in admin perform such action and delete arbitrary users from the subscribed list

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webfwd mail subscribe list