Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-1349

Опубликовано: 16 мая 2022
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any users (with privileges as low as Subscriber) to delete the profile pictures of any other user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:2code:wpqa_builder:*:*:*:*:*:wordpress:*:*
Версия до 5.2 (исключая)

EPSS

Процентиль: 43%
0.00204
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-287
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any users (with privileges as low as Subscriber) to delete the profile pictures of any other user.

EPSS

Процентиль: 43%
0.00204
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-287
NVD-CWE-Other