plugin

Bulk Delete Users By Email Vulnerabilities

2 known security issues reported for the Bulk Delete Users By Email WordPress plugin. Most recent disclosed Dec 2, 2022.

1 high 1 medium

Running Bulk Delete Users By Email on your site? Check whether your installed version is affected.

Scan your site free

Bulk Delete Users by Email <= 1.2 - Cross-Site Request Forgery

high

The Bulk Delete Users by Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the baw_settings_page function. This makes it possible for unauthenticated attackers to delete users, via forged request granted...

CVSS:
8.8
Affected:
up to 1.2
Fixed in:
2.0.0
Disclosed:
Dec 2, 2022

CVE-2022-4266 on NVD →

Bulk Delete Users by Email <= 1.2 - Reflected Cross-Site Scripting

medium

The Bulk Delete Users by Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'de-text' parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 1.2
Fixed in:
2.0.0
Disclosed:
Dec 2, 2022

CVE-2022-4267 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database