PT-2022-13091 · WordPress · Anycomment

Brandon Roldan

·

Published

2022-02-21

·

Updated

2022-02-28

·

CVE-2022-0279

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions AnyComment WordPress plugin versions prior to 0.2.18
Description The issue is related to a race condition that occurs when liking or disliking a comment or reply. This could allow any authenticated user to quickly increase their own rating or decrease the rating of other users.
Recommendations For versions prior to 0.2.18, update to version 0.2.18 or later to resolve the issue. As a temporary workaround, consider restricting the like/dislike functionality to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0279

Affected Products

Anycomment