CVE Database /
CVE-2022-0279
CVE · Low
CVE-2022-0279 — AnyComment [anycomment] < 0.2.18
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0279
|
AnyComment [anycomment] < 0.2.18 |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
Low
3.1
|
< 0.2.18
|
0.2.18 |
2022-01-19 |
—
|
CVE-2022-0279
The AnyComment plugin in versions earlier than 0.2.18 contains a race condition vulnerability in its like and dislike functionality for comments and replies. This flaw could permit any logged-in user to rapidly increase their own rating score or decrease another user's rating by exploiting timing issues during concurrent requests. The issue affects the comment rating system and could be leveraged to manipulate user reputation metrics on affected WordPress installations.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings