// For flags

CVE-2022-1425

WPQA < 5.2 - Subscriber+ Private Message Disclosure via IDOR

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any user being able to read messages for any other users via a Insecure Direct Object Reference (IDOR) vulnerability.

El plugin WPQA Builder de WordPress versiones anteriores a 5.2, usado como plugin complementario de Discy y Himer , no comprueba que el message_id de la acción ajax wpqa_message_view pertenezca al usuario solicitante, lo que conlleva a que cualquier usuario pueda leer los mensajes de cualquier otro usuario por medio de una vulnerabilidad de tipo Insecure Direct Object Reference (IDOR)

*Credits: Veshraj Ghimire
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-04-21 CVE Reserved
  • 2022-04-21 CVE Published
  • 2023-12-07 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
2code
Search vendor "2code"
Wpqa Builder
Search vendor "2code" for product "Wpqa Builder"
< 5.2
Search vendor "2code" for product "Wpqa Builder" and version " < 5.2"
wordpress
Affected