MEDIUM
WPQA < 5.2 - Subscriber+ Arbitrary Profile Picture Deletion via IDOR
Published May 16, 2022
4.3
MEDIUMCVSS 3.1
EPSS 0.65%
Description
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any users (with privileges as low as Subscriber) to delete the profile pictures of any other user.
Affected products
- Vendor n/a Product WPQA Builder Plugin Defaultn/a
- Version 5.2StatusaffectedConstraints<5.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | WPQA Builder Plugin | n/a |
|
- < 5.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24671 Advisory
- https://wpscan.com/vulnerability/7ee95a53-5fe9-404c-a77a-d1218265e4aa x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24671 | Advisory | |
| https://wpscan.com/vulnerability/7ee95a53-5fe9-404c-a77a-d1218265e4aa | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published May 16, 2022
Updated Aug 3, 2024
Reserved Apr 13, 2022
Link CVE-2022-1349
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-24671 Assigner WPScan
Published May 16, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-24671