Vulnerabilities > 2Code > Wpqa Builder > Low

DATE CVE VULNERABILITY TITLE RISK
2023-01-09 CVE-2022-3343 Unspecified vulnerability in 2Code Wpqa Builder 5.2/5.7/5.9
The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the site by having another user send repeated follow actions to them.
network
low complexity
2code
3.5
2022-05-16 CVE-2022-1051 Cross-site Scripting vulnerability in 2Code Wpqa Builder
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.
network
2code CWE-79
3.5