Description
WordPress Plugin WPQA-Builder forms Addon For WordPress is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to inflate follower counts of others by sending repeat follow requests. WordPress Plugin WPQA-Builder forms Addon For WordPress version 5.9.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.9.3 or latest
References
Related Vulnerabilities
WordPress Plugin DVS Custom Notification Multiple Cross-Site Request Forgery Vulnerabilities (1.0.1)
PHP Other Vulnerability (CVE-2009-4017)
WordPress Plugin CMP-Coming Soon & Maintenance by NiteoThemes Security Bypass (3.8.1)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5106)
WordPress Plugin WP Construction Mode Cross-Site Request Forgery (1.8)