CVE · Low

CVE-2022-0279 — AnyComment [anycomment] < 0.2.18

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0279 AnyComment [anycomment] < 0.2.18 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Low 3.1 < 0.2.18 0.2.18 2022-01-19

CVE-2022-0279

The AnyComment plugin in versions earlier than 0.2.18 contains a race condition vulnerability in its like and dislike functionality for comments and replies. This flaw could permit any logged-in user to rapidly increase their own rating score or decrease another user's rating by exploiting timing issues during concurrent requests. The issue affects the comment rating system and could be leveraged to manipulate user reputation metrics on affected WordPress installations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.