CVE-2022-0279

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
21/02/2022
Last modified:
28/02/2022

Description

The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bologer:anycomment:*:*:*:*:*:wordpress:*:* 0.2.18 (excluding)