CVE-2022-1598 Information

Description

The WPQA Builder WordPress plugin before 5.4 which is a companion to the Discy and Himer lacks authentication in a REST API endpoint allowing unauthenticated users to discover private questions sent between users on the site.

Reference

https://wpscan.com/vulnerability/0416ae2f-5670-4080-a88d-3484bb19d8c8

Share on: