Vulnerability CVE-2022-3343


Published: 2023-01-09   Modified: 2023-01-10

Description:
The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the site by having another user send repeated follow actions to them.

Type:

CWE-639

(Authorization Bypass Through User-Controlled Key)

 References:
https://wpscan.com/vulnerability/e507b1b5-1a56-4b2f-b7e7-e22f6da1e32a

Copyright 2026, cxsecurity.com

 

Back to Top