Skip to main content

Software intelligence

Wpqa vulnerabilities

10 tracked advisories · slug wpqa

Important: Wpqa appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works

Tracked advisories

10

Latest advisory

12 June 2024

CISA KEV matches

0

In this WordPress feed

WordPress slug

wpqa

Plugin

What this means for Wpqa

This catalog lists 10 known advisories affecting Wpqa. The most recent was published on 12 June 2024. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.

Latest issues

  • WPQA - Builder forms Addon For WordPress plugin <= 6.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

    May allow attackers to run scripts in visitors' browsers or hijack admin sessions.

    Published 12 June 2024

  • WPQA Builder <= 6.1.0 - Cross-Site Request Forgery

    May trick authenticated users into performing unintended actions.

    Published 12 June 2024

  • WPQA - Builder forms Addon For WordPress (<= 5.9.2), Himer (<= 1.9.3) and Discy (<= 5.5.3) - Authenticated (Subscriber+) Insecure Direct Object Reference

    This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.

    Published 13 December 2022

Vulnerability types

  • Cross-site scripting3
  • CSRF2

Authentication (inferred from titles)

  • Unauthenticated1
  • Authenticated2
  • Unspecified7

Advisory history

Known Wpqa advisories published by month.

All advisories

Check whether your installed version is affected

SiteRespond Defence matches your installed Wpqa version against this catalog when the Defence plugin is connected to your WordPress site.