plugin

Gd Star Rating Vulnerabilities

18 known security issues reported for the Gd Star Rating WordPress plugin. Most recent disclosed Jul 3, 2015.

2 high 2 medium

Running Gd Star Rating on your site? Check whether your installed version is affected.

Scan your site free

GD Star Rating [gd-star-rating] < 1.9.8 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.9.8
Fixed in:
1.9.8
Disclosed:
Jul 3, 2015

GD Star Rating [gd-star-rating] < 1.9.17 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.9.17
Fixed in:
1.9.17
Disclosed:
Jul 3, 2015

GD Star Rating [gd-star-rating] < 1.9.19 (closed)

unknown

Because of this vulnerability, attackers can bypass certain security restrictions. Update the plugin.

Affected:
up to 1.9.19
Fixed in:
1.9.19
Disclosed:
Jul 3, 2015

GD Star Rating [gd-star-rating] <= 1.9.22 (closed)

unknown

[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct (1) SQL injection attacks via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php or (2) cro...

Affected:
up to 1.9.22
Fixed in:
1.9.22
Disclosed:
Jan 12, 2015

CVE-2014-2838 on NVD →

GD Star Rating [gd-star-rating] <= 1.9.22 (closed)

unknown

[en] SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.

Affected:
up to 1.9.22
Fixed in:
1.9.22
Disclosed:
Jan 12, 2015

CVE-2014-2839 on NVD →

GD Star Rating <= 1.9.22 - Cross-Site Request Forgery

high

Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 1.9.22 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct (1) SQL injection attacks via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php or (2) cross-s...

CVSS:
8.8
Affected:
up to 1.9.22
Fix:
No patched version reported
Disclosed:
Mar 28, 2014

CVE-2014-2838 on NVD →

GD Star Rating <= 1.9.22 - Blind SQL Injection

high

SQL injection vulnerability in the GD Star Rating plugin 1.9.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.

CVSS:
7.2
Affected:
up to 1.9.22
Fix:
No patched version reported
Disclosed:
Mar 28, 2014

CVE-2014-2839 on NVD →

GD Star Rating < 1.9.17 - Cross-Site Scripting

medium

The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'tpl_section' parameter in versions before 1.9.17 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.9.17
Fixed in:
1.9.17
Disclosed:
May 15, 2012

GD Star Rating [gd-star-rating] < 1.9.17

unknown

The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'tpl_section' parameter in versions before 1.9.17 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.9.17
Fixed in:
1.9.17
Disclosed:
May 15, 2012

GD Star Rating [gd-star-rating] < 1.9.11 (closed)

unknown

GD Star Rating plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 1.9.11
Fixed in:
1.9.11
Disclosed:
Oct 12, 2011

GD Star Rating [gd-star-rating] < 1.1 (closed)

unknown

This WordPress GD Star Rating plugin's "votes" parameter is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jun 8, 2011

GD Star Rating <= 1.9.22 - Cross-Site Scripting

medium

The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpfn' parameter in versions up to, and including, 1.9.22 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.9.22
Fix:
No patched version reported
Disclosed:
Feb 22, 2011

GD Star Rating [gd-star-rating] < 1.9.8 (closed)

unknown

This GD Star Rating plugin's "wpfn" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication...

Affected:
up to 1.9.8
Fixed in:
1.9.8
Disclosed:
Feb 22, 2011

GD Star Rating [gd-star-rating] <= 1.9.22 (unfixed)

unknown

The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpfn' parameter in versions up to, and including, 1.9.22 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.9.22
Fix:
No patched version reported
Disclosed:
Feb 22, 2011

GD Star Rating [gd-star-rating] <= 1.9.10 (unfixed + closed)

unknown

The gd-star-rating WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 1.9.10
Fix:
No patched version reported

GD Star Rating [gd-star-rating] <= 1.9.16 (unfixed + closed)

unknown

The gd-star-rating WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.9.16
Fix:
No patched version reported

GD Star Rating [gd-star-rating] < 1.9.19 (closed)

unknown

The gd-star-rating WordPress plugin was affected by an Export Security Bypass security vulnerability.

Affected:
up to 1.9.19
Fixed in:
1.9.19

GD Star Rating [gd-star-rating] <= 1.9.7 (unfixed + closed)

unknown

The gd-star-rating WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.9.7
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database