WordPress WPQA plugin before 5.5 is susceptible to improper access control. The plugin lacks authentication in a REST API endpoint. An attacker can potentially discover private questions sent between users on the site.
View the template here CVE-2022-1598.yaml
References:
https://wpscan.com/vulnerability/0416ae2f-5670-4080-a88d-3484bb19d8c8