GD Star Rating [gd-star-rating] < 1.9.8 (closed)
unknownBecause of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
- Affected:
- up to 1.9.8
- Fixed in:
- 1.9.8
- Disclosed:
- Jul 3, 2015
plugin
18 known security issues reported for the Gd Star Rating WordPress plugin. Most recent disclosed Jul 3, 2015.
Running Gd Star Rating on your site? Check whether your installed version is affected.
Scan your site freeBecause of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Because of this vulnerability, attackers can bypass certain security restrictions. Update the plugin.
[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct (1) SQL injection attacks via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php or (2) cro...
[en] SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.
Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 1.9.22 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct (1) SQL injection attacks via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php or (2) cross-s...
SQL injection vulnerability in the GD Star Rating plugin 1.9.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.
The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'tpl_section' parameter in versions before 1.9.17 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'tpl_section' parameter in versions before 1.9.17 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
GD Star Rating plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.
This WordPress GD Star Rating plugin's "votes" parameter is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpfn' parameter in versions up to, and including, 1.9.22 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
This GD Star Rating plugin's "wpfn" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication...
The GD Star Rating plugin for WordPress is vulnerable to Cross-Site Scripting via the 'wpfn' parameter in versions up to, and including, 1.9.22 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
The gd-star-rating WordPress plugin was affected by a SQL Injection security vulnerability.
The gd-star-rating WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
The gd-star-rating WordPress plugin was affected by an Export Security Bypass security vulnerability.
The gd-star-rating WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free