Comment Rating [comment-rating] < 2.9.33 (closed)
unknown
This Comment Rating plugin is prone to multiple vulnerabilities such as comment rating SQL injection and BYPASS.
Update the plugin.
- Affected:
- up to 2.9.33
- Fixed in:
- 2.9.33
- Disclosed:
- Feb 27, 2013
Comment Rating <= 2.9.32 - SQL Injection
critical
The Comment Rating plugin for WordPress is vulnerable to generic SQL Injection via the 'ck_ips' parameter in versions up to, and including, 2.9.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...
- CVSS:
- 9.8
- Affected:
- up to 2.9.32
- Fix:
- No patched version reported
- Disclosed:
- Feb 21, 2013
Comment Rating [comment-rating] <= 2.9.32 (unfixed)
unknown
The Comment Rating plugin for WordPress is vulnerable to generic SQL Injection via the 'ck_ips' parameter in versions up to, and including, 2.9.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...
- Affected:
- up to 2.9.32
- Fix:
- No patched version reported
- Disclosed:
- Feb 21, 2013
Comment Rating [comment-rating] < 2.9.21 (closed)
unknown
WordPress Comment Rating plugin's "path" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentic...
- Affected:
- up to 2.9.21
- Fixed in:
- 2.9.21
- Disclosed:
- Jan 3, 2012
Comment Rating [comment-rating] < 2.9.3 (closed)
unknown
There are several vulnerabilities in this plugin.
First vulnerability type is path disclosure. The issue exists due to failure in the "/wp-content/plugins/comment-rating/comment-rating-options.php" script. There is possible to generate an error which will disclose the full path of the script. In this way an attacker...
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.3
- Disclosed:
- Feb 23, 2011
Comment Rating [comment-rating] < 2.9.24 (closed)
unknown
The comment-rating WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.
- Affected:
- up to 2.9.24
- Fixed in:
- 2.9.24
Comment Rating [comment-rating] <= 2.9.32 (unfixed + closed)
unknown
The comment-rating WordPress plugin was affected by a Security Bypass Weakness & SQL Injection security vulnerability.
- Affected:
- up to 2.9.32
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database