The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-04-25T15:50:41
Updated: 2024-08-03T19:42:17.205Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24800
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-04-25T16:16:06.930
Modified: 2022-05-05T12:00:05.737
Link: CVE-2021-24800
Redhat
No data.