CVE-2021-24800

MEDIUM

DW Question & Answer Pro <1.3.4 - Info Disclosure

Title source: llm

Description

The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.

Exploits (1)

github NO CODE 2 stars
by tomorroisnew · poc
https://github.com/tomorroisnew/CVE/tree/main/CVE-2021-24800

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-639
Status published
Products (1)
designwall/dw_question_\&_answer < 1.3.4
Published Apr 25, 2022
Tracked Since Feb 18, 2026