WordPress Plugin Vulnerabilities
DW Question & Answer Pro < 1.3.7 - Arbitrary Comment Edition via IDOR
Description
The plugin does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
Vendor was notified via Envato on September 28th, 2021, but did not properly fix the issue and was notified numerous times since.
Proof of Concept
As any authenticated user, post a comment and edit it while capturing the request made, then change the comment_id parameter to the comment to edit
Affects Plugins
References
CVE
YouTube Video
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Brandon Roldan
Submitter
Brandon Roldan
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-03-29 (about 1 years ago)
Added
2022-03-29 (about 1 years ago)
Last Updated
2023-02-02 (about 10 months ago)