Lucene search

K
cvelistWPScanCVELIST:CVE-2022-3688
HistoryNov 21, 2022 - 12:00 a.m.

CVE-2022-3688 WPQA < 5.9 - Follow/Unfollow via CSRF

2022-11-2100:00:00
WPScan
www.cve.org
3
wpqa builder
wordpress
csrf
vulnerability

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

61.3%

The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could allow attackers to make logged in users perform such actions via CSRF attacks

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "WPQA Builder",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "5.9"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

61.3%

Related for CVELIST:CVE-2022-3688