plugin

Comment Rating Vulnerabilities

7 known security issues reported for the Comment Rating WordPress plugin. Most recent disclosed Feb 27, 2013.

1 critical

Running Comment Rating on your site? Check whether your installed version is affected.

Scan your site free

Comment Rating [comment-rating] < 2.9.33 (closed)

unknown

This Comment Rating plugin is prone to multiple vulnerabilities such as comment rating SQL injection and BYPASS. Update the plugin.

Affected:
up to 2.9.33
Fixed in:
2.9.33
Disclosed:
Feb 27, 2013

Comment Rating <= 2.9.32 - SQL Injection

critical

The Comment Rating plugin for WordPress is vulnerable to generic SQL Injection via the 'ck_ips' parameter in versions up to, and including, 2.9.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...

CVSS:
9.8
Affected:
up to 2.9.32
Fix:
No patched version reported
Disclosed:
Feb 21, 2013

Comment Rating [comment-rating] <= 2.9.32 (unfixed)

unknown

The Comment Rating plugin for WordPress is vulnerable to generic SQL Injection via the 'ck_ips' parameter in versions up to, and including, 2.9.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...

Affected:
up to 2.9.32
Fix:
No patched version reported
Disclosed:
Feb 21, 2013

Comment Rating [comment-rating] < 2.9.21 (closed)

unknown

WordPress Comment Rating plugin's "path" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentic...

Affected:
up to 2.9.21
Fixed in:
2.9.21
Disclosed:
Jan 3, 2012

Comment Rating [comment-rating] < 2.9.3 (closed)

unknown

There are several vulnerabilities in this plugin. First vulnerability type is path disclosure. The issue exists due to failure in the "/wp-content/plugins/comment-rating/comment-rating-options.php" script. There is possible to generate an error which will disclose the full path of the script. In this way an attacker...

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Feb 23, 2011

Comment Rating [comment-rating] < 2.9.24 (closed)

unknown

The comment-rating WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.

Affected:
up to 2.9.24
Fixed in:
2.9.24

Comment Rating [comment-rating] <= 2.9.32 (unfixed + closed)

unknown

The comment-rating WordPress plugin was affected by a Security Bypass Weakness &amp; SQL Injection security vulnerability.

Affected:
up to 2.9.32
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database