Description
WordPress Plugin WPQA-Builder forms Addon For WordPress is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to inflate follower counts of others by sending repeat follow requests. WordPress Plugin WPQA-Builder forms Addon For WordPress version 5.9.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.9.3 or latest
References
Related Vulnerabilities
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2025-3635)
Oracle JRE CVE-2013-2456 Vulnerability (CVE-2013-2456)
WordPress Plugin Disqus Comment System Multiple Vulnerabilities (2.75)
WordPress Plugin Global Content Blocks 'gcb_export.php' SQL Injection (1.2)
WordPress MU 'wp-includes/wpmu-functions.php' Cross-Site Scripting Vulnerability (1.0 - 2.6)