The Ultimate FAQ WordPress plugin before 2.1.2 does not...
Moderate severity
Unreviewed
Published
Jan 25, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jan 24, 2022
Published to the GitHub Advisory Database
Jan 25, 2022
Last updated
Jan 29, 2023
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions
References