Vulnerability Details CVE-2022-3343
The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the site by having another user send repeated follow actions to them.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.9%
CVSS Severity
CVSS v3 Score 3.5
Products affected by CVE-2022-3343
-
cpe:2.3:a:2code:wpqa_builder:-
-
cpe:2.3:a:2code:wpqa_builder:5.2
-
cpe:2.3:a:2code:wpqa_builder:5.7
-
cpe:2.3:a:2code:wpqa_builder:5.9