Vulnerability Description
The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the site by having another user send repeated follow actions to them.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 2Code | Wpqa Builder | < 5.9.3 |
References
- https://wpscan.com/vulnerability/e507b1b5-1a56-4b2f-b7e7-e22f6da1e32aExploitThird Party Advisory
- https://wpscan.com/vulnerability/e507b1b5-1a56-4b2f-b7e7-e22f6da1e32aExploitThird Party Advisory
FAQ
What is CVE-2022-3343?
CVE-2022-3343 is a vulnerability with a CVSS score of 3.5 (LOW). The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the w...
How severe is CVE-2022-3343?
CVE-2022-3343 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3343?
Check the references section above for vendor advisories and patch information. Affected products include: 2Code Wpqa Builder.