Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Whoisbinit

#50810of 53,624
4.3Total CVSS
Vulnerabilities · 1
PT-2022-13819
4.3
2022-05-16
WordPress · Wpqa Builder Plugin · CVE-2022-1349
**Name of the Vulnerable Software and Affected Versions** WPQA Builder Plugin versions prior to 5.2 **Description** The issue allows any user with privileges as low as Subscriber to delete the profile pictures of other users due to a lack of validation for the `image id` parameter in the `wpqa remove image` ajax action. **Recommendations** For versions prior to 5.2, update to version 5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the `wpqa remove image` ajax action to prevent unauthorized deletion of profile pictures.