Lucene search

K
wpvulndbBrandon RoldanWPVDB-ID:A6BE3FCF-60F7-4F13-B773-871A7296113C
HistoryMar 29, 2022 - 12:00 a.m.

DW Question & Answer Pro <= 1.3.4 - Multiple CSRF

2022-03-2900:00:00
Brandon Roldan
wpscan.com
10

0.001 Low

EPSS

Percentile

25.9%

The plugin does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a question status. Vendor was notified via Envato on September 28th, 2021, but did not properly fix the issue and was notified numerous times since.

PoC

CSRF to update_comment CSRF to update a question status

CPENameOperatorVersion
dw-question-answer-proeq*

0.001 Low

EPSS

Percentile

25.9%

Related for WPVDB-ID:A6BE3FCF-60F7-4F13-B773-871A7296113C