CVE-2022-2198
22.08.2022, 15:15
The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute forced.Enginsight
Vendor | Product | Version |
---|---|---|
2code | wpqa_builder | 𝑥 < 5.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration