WordPress WPQA plugin before 5.5 is susceptible to improper access control. The plugin lacks authentication in a REST API endpoint. An attacker can potentially discover private questions sent between users on the site.
id: CVE-2022-1598
info:
name: WordPress WPQA <5.5 - Improper Access Control
author: veshraj
s
...