Vulnerabilities > Speakdigital
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-26 | CVE-2022-4266 | Unspecified vulnerability in Speakdigital Bulk Delete Users BY Email 1.2 The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete non admin users by knowing their email via a CSRF attack | 6.5 |
2022-12-26 | CVE-2022-4267 | Unspecified vulnerability in Speakdigital Bulk Delete Users BY Email 1.2 The Bulk Delete Users by Email WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | 6.1 |