QID 150499
Date Published: 2022-04-13
QID 150499: WordPress AnyComment Plugin: Comment Rating Increase/Decrease via Race Condition Vulnerability (CVE-2022-0279)
AnyComment is a plugin for WordPress, it allows users to easily add their comments via social networks.
The plugin is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users.
Affected Versions:
AnyComment WordPress plugin before 0.2.18
QID Detection Logic:
This QID sends an HTTP GET request and retrieves a vulnerable version of the AnyComment plugin running on the target application.
Successful exploitation could allow an authenticated user to quickly raise their rating or lower the rating of other users.
Solution
Customers are advised to upgrade to AnyComment 0.2.18 or later version to remediate this vulnerability. For more information regarding this vulnerability please refer WPScan.
Vendor References
CVEs related to QID 150499
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WPScan |
|
||
| WordPress |
|