WordPress Plugin Vulnerabilities

WPQA < 5.7 - Subscriber+ Private Message Disclosure via IDOR

Description

The plugin which is a companion plugin to the Hilmer and Discy themes, does not check authorization before displaying private messages, allowing any logged in user to read other users private message using the message id, which can easily be brute forced.

Proof of Concept

Affects Plugins

Fixed in 5.7

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Bikram kharal
Submitter
Bikram kharal
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-08-01 (about 3 years ago)
Added
2022-08-01 (about 3 years ago)
Last Updated
2023-04-30 (about 2 years ago)

Other