Record summary

CVE-2022-1598 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WPQA Builder

Default status: unaffected

CVE ListBefore 5.5affected

Proofs of concept

1

Repository PoCs

GitHubV35HR4J/CVE-2022-1598Repository PoCby V35HR4JStars: 1Not analyzed2 files

2.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress WPQA <5.5 - Improper Access ControlCVSS 5.3

WordPress WPQA plugin before 5.5 is susceptible to improper access control. The plugin lacks authentication in a REST API endpoint. An attacker can potentially discover private questions sent between users on the site.

Impact

This vulnerability can result in unauthorized access to sensitive information, potentially leading to data breaches or unauthorized actions.

Remediation

Update the WPQA plugin to version 5.5 or later to fix the improper access control issue.

WeaknessesCWE-306
Authorsveshraj
Template tagscvecve2022wordpresswp-pluginwpqaidorwpscan2codevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:2code:wpqa_builder:*:*:*:*:*:wordpress:*:*
Google: inurl:/wp-content/plugins/wpqa

Source: ProjectDiscovery

References

2