Vulnerability Description
The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute forced.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 2Code | Wpqa Builder | < 5.7 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/867248f2-d497-4ea8-b3f8-0f2e8aaaa2bdExploitThird Party Advisory
- https://wpscan.com/vulnerability/867248f2-d497-4ea8-b3f8-0f2e8aaaa2bdExploitThird Party Advisory
FAQ
What is CVE-2022-2198?
CVE-2022-2198 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read ...
How severe is CVE-2022-2198?
CVE-2022-2198 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2198?
Check the references section above for vendor advisories and patch information. Affected products include: 2Code Wpqa Builder.