Lucene search

K
wpexploitBrandon RoldanWPEX-ID:CD37CA81-D683-4955-BC97-60204CB9C346
HistoryMar 29, 2022 - 12:00 a.m.

DW Question & Answer Pro <= 1.3.4 - Arbitrary Comment Edition via IDOR

2022-03-2900:00:00
Brandon Roldan
41

0.001 Low

EPSS

Percentile

24.8%

The plugin does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments. Vendor was notified via Envato on September 28th, 2021, but did not properly fix the issue and was notified numerous times since.

As any authenticated user, post a comment and edit it while capturing the request made, then change the comment_id parameter to the comment to edit

0.001 Low

EPSS

Percentile

24.8%

Related for WPEX-ID:CD37CA81-D683-4955-BC97-60204CB9C346