Lucene search

K
wpvulndbHarsh TandelWPVDB-ID:E507B1B5-1A56-4B2F-B7E7-E22F6DA1E32A
HistoryDec 13, 2022 - 12:00 a.m.

WPQA < 5.9.3 - Missing validation lead to functionality abuse

2022-12-1300:00:00
Harsh Tandel
wpscan.com
9
wpqa plugin
companion plugin
discy theme
himer theme
user validation
functionality abuse

EPSS

0.001

Percentile

25.4%

The plugin (which is a companion plugin used with Discy and Himer themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the site by having another user send repeated follow actions to them.

PoC

EPSS

0.001

Percentile

25.4%

Related for WPVDB-ID:E507B1B5-1A56-4B2F-B7E7-E22F6DA1E32A