plugin

Rate Star Review Vulnerabilities

5 known security issues reported for the Rate Star Review WordPress plugin. Most recent disclosed May 11, 2026.

3 medium

Running Rate Star Review on your site? Check whether your installed version is affected.

Scan your site free

Rate Star Review Vote <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'rating_id' Parameter

medium

The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() check. When the 'for...

CVSS:
4.3
Affected:
up to 1.6.4
Fixed in:
1.6.5
Disclosed:
May 11, 2026

CVE-2026-4301 on NVD →

Rate Star Review Vote &#8211; AJAX Reviews, Votes, Star Ratings [rate-star-review] < 1.6.4

unknown

[en] The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Jan 18, 2025

CVE-2024-13392 on NVD →

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

CVSS:
6.4
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Jan 17, 2025

CVE-2024-13392 on NVD →

Rate Star Review Vote &#8211; AJAX Reviews, Votes, Star Ratings [rate-star-review] < 1.5.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows Reflected XSS.This issue affects Rate Star Review – AJAX Reviews for Content, with Star Ratings: from n/a through 1.5.1.

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jan 8, 2024

CVE-2023-52213 on NVD →

Rate Star Review <= 1.5.1 - Reflected Cross-Site Scripting

medium

The Rate Star Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...

CVSS:
6.1
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jan 3, 2024

CVE-2023-52213 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database