WPQA < 5.2 - Subscriber+ Arbitrary Profile Picture Deletion via IDOR
CVE-2022-1349

4.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
16 May 2022

Summary

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any users (with privileges as low as Subscriber) to delete the profile pictures of any other user.

Affected Version(s)

WPQA Builder Plugin 5.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Binit Ghimire
.