Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 4.2.5
unknown
[en] The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.4 via the get_post_status() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to vote on unpubl...
- Affected:
- up to 4.2.5
- Fixed in:
- 4.2.5
- Disclosed:
- Dec 13, 2024
CVE-2024-12309 on NVD →
Rate My Post – Star Rating Plugin by FeedbackWP <= 4.2.4 - Unauthenticated Voting On Scheduled Posts
medium
The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.4 via the get_post_status() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to vote on unpublished...
- CVSS:
- 5.3
- Affected:
- up to 4.2.4
- Fixed in:
- 4.2.5
- Disclosed:
- Dec 12, 2024
CVE-2024-12309 on NVD →
Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.4.3
unknown
[en] Authentication Bypass by Spoofing vulnerability in FeedbackWP Rate my Post – WP Rating System allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.2.
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Jun 4, 2024
CVE-2023-51667 on NVD →
Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.4.5
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.4.
- Affected:
- up to 3.4.5
- Fixed in:
- 3.4.5
- Disclosed:
- Apr 24, 2024
CVE-2024-32823 on NVD →
Rate My Post – Star Rating Plugin by FeedbackWP <= 3.4.4 - Insecure Direct Object Reference
medium
The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.4 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to rate private posts.
- CVSS:
- 5.3
- Affected:
- up to 3.4.4
- Fixed in:
- 3.4.5
- Disclosed:
- Apr 22, 2024
CVE-2024-32823 on NVD →
Rate my Post – WP Rating System <= 3.4.2 - IP Address Spoofing
medium
The Rate my Post – WP Rating System plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.4.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to vote on...
- CVSS:
- 5.3
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Dec 27, 2023
CVE-2023-51667 on NVD →
Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.4.2
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Dec 21, 2023
CVE-2023-49765 on NVD →
Rate my Post - WP Rating System <= 3.4.1 - Insecure Direct Object Reference
medium
The Rate my Post - WP Rating System plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.4.1 due to missing validation on a user controlled key. This can allow users with publishing access to manipulate feedback and ratings.
- CVSS:
- 4.3
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Aug 11, 2023
CVE-2023-49765 on NVD →
Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.4.2
unknown
The Rate my Post - WP Rating System plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.4.1 due to missing validation on a user controlled key. This can allow users with publishing access to manipulate feedback and ratings.
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Aug 11, 2023
Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.9
unknown
[en] The Rate my Post WordPress plugin before 3.3.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
- Affected:
- up to 3.3.9
- Fixed in:
- 3.3.9
- Disclosed:
- Jan 23, 2023
CVE-2022-4673 on NVD →
Rate my Post – WP Rating System <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Rate my Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.9
- Disclosed:
- Dec 27, 2022
CVE-2022-4673 on NVD →
Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress.
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.5
- Disclosed:
- Sep 23, 2022
CVE-2022-40671 on NVD →
Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.5
unknown
[en] Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes.
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.5
- Disclosed:
- Sep 23, 2022
CVE-2022-40310 on NVD →
Rate my Post – WP Rating System <= 3.3.4 - Cross-Site Request Forgery
high
The Rate my Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.4. This is due to missing or incorrect nonce validation on the has_valid_nonce function. This makes it possible for unauthenticated attackers to vote on posts, via forged request granted they can tric...
- CVSS:
- 8.8
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.5
- Disclosed:
- Sep 14, 2022
CVE-2022-40671 on NVD →
Rate my Post – WP Rating System <= 3.3.4 - Race Condition
medium
The Rate my Post plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 3.3.4. This can lead to unpredictable post rating changes when certain conditions are met.
- CVSS:
- 4.3
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.5
- Disclosed:
- Sep 1, 2022
CVE-2022-40310 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database