CVE-2022-1598
The WPQA Builder WordPress plugin before 5.4 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.
Date published : 2022-06-06
https://wpscan.com/vulnerability/0416ae2f-5670-4080-a88d-3484bb19d8c8
