plugin

Kk Star Ratings Vulnerabilities

16 known security issues reported for the Kk Star Ratings WordPress plugin. Most recent disclosed Aug 21, 2026.

1 high 6 medium

Running Kk Star Ratings on your site? Check whether your installed version is affected.

Scan your site free

kk Star Ratings <= 5.4.10.3 - Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter

medium

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode...

CVSS:
5.3
Affected:
up to 5.4.10.3
Fixed in:
5.4.10.4
Disclosed:
Aug 21, 2026

CVE-2026-3424 on NVD →

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.4.6

unknown

[en] Missing Authorization vulnerability in FeedbackWP kk Star Ratings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects kk Star Ratings: from n/a through 5.4.5.

Affected:
up to 5.4.6
Fixed in:
5.4.6
Disclosed:
Jan 2, 2025

CVE-2023-46639 on NVD →

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.4.10.1

unknown

[en] The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This ma...

Affected:
up to 5.4.10.1
Fixed in:
5.4.10.1
Disclosed:
Dec 21, 2024

CVE-2024-11977 on NVD →

kk Star Ratings – Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution

high

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes i...

CVSS:
7.3
Affected:
up to 5.4.10
Fixed in:
5.4.10.2
Disclosed:
Dec 20, 2024

CVE-2024-11977 on NVD →

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.4.4

unknown

[en] Missing Authorization vulnerability in FeedbackWP kk Star Ratings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects kk Star Ratings: from n/a through 5.4.3.

Affected:
up to 5.4.4
Fixed in:
5.4.4
Disclosed:
Dec 13, 2024

CVE-2023-36528 on NVD →

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.2.9

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 5.2.9
Fixed in:
5.2.9
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.4.6

unknown

[en] The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.

Affected:
up to 5.4.6
Fixed in:
5.4.6
Disclosed:
Nov 27, 2023

CVE-2023-4642 on NVD →

kk Star Ratings <= 5.4.5 - Race Condition to Multiple User Voting

medium

The kk Star Ratings plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 5.4.5. This is due to insufficient controls and checks on a user voting. This makes it possible for unauthenticated attackers to provides ratings more than a single time.

CVSS:
5.3
Affected:
up to 5.4.5
Fixed in:
5.4.6
Disclosed:
Nov 6, 2023

CVE-2023-4642 on NVD →

kk Star Ratings <= 5.4.5 - Missing Authorization

medium

The kk Star Ratings plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on an unknown function in versions up to, and including, 5.4.5. This makes it possible for unauthenticated attackers to make use of this functionality. The exact impact of this vulnerability is...

CVSS:
5.3
Affected:
up to 5.4.5
Fixed in:
5.4.6
Disclosed:
Oct 25, 2023

CVE-2023-46639 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
3.0.0 – 5.4.4
Fixed in:
5.4.5
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

kk Star Ratings <= 5.4.3 - IP Spoofing to Protection Mechanism Bypass

medium

The kk Star Ratings plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.4.3. This is due to the plugin prioritizing obtaining a visitor's IP address from a spoofable HTTP header over PHP's REMOTE_ADDR. Attackers can supply a header with with a different IP Address that can be u...

CVSS:
5.3
Affected:
up to 5.4.3
Fixed in:
5.4.4
Disclosed:
Jul 17, 2023

CVE-2023-36528 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 5.2.9
Fixed in:
5.2.9
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.2.9

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 5.2.9
Fixed in:
5.2.9
Disclosed:
Mar 4, 2022

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.2.9

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress kk Star Ratings plugin (versions < 5.2.9).

Affected:
up to 5.2.9
Fixed in:
5.2.9
Disclosed:
Feb 28, 2022

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.2.9

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress kk Star Ratings plugin (versions < 5.2.9).

Affected:
up to 5.2.9
Fixed in:
5.2.9
Disclosed:
Feb 28, 2022

kk Star Ratings &#8211; Rate Post &amp; Collect User Feedbacks [kk-star-ratings] < 5.4.5

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 5.4.5
Fixed in:
5.4.5

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database