Vulnerability Description
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bologer | Anycomment | < 0.2.18 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/43a4b2d3-1bd5-490c-982c-bb7120595865ExploitThird Party Advisory
- https://wpscan.com/vulnerability/43a4b2d3-1bd5-490c-982c-bb7120595865ExploitThird Party Advisory
FAQ
What is CVE-2022-0279?
CVE-2022-0279 is a vulnerability with a CVSS score of 3.1 (LOW). The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the...
How severe is CVE-2022-0279?
CVE-2022-0279 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0279?
Check the references section above for vendor advisories and patch information. Affected products include: Bologer Anycomment.