Rate Star Review Vote <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'rating_id' Parameter
medium
The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() check. When the 'for...
- CVSS:
- 4.3
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.5
- Disclosed:
- May 11, 2026
CVE-2026-4301 on NVD →
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings [rate-star-review] < 1.6.4
unknown
[en] The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This...
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Jan 18, 2025
CVE-2024-13392 on NVD →
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...
- CVSS:
- 6.4
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Jan 17, 2025
CVE-2024-13392 on NVD →
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings [rate-star-review] < 1.5.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows Reflected XSS.This issue affects Rate Star Review – AJAX Reviews for Content, with Star Ratings: from n/a through 1.5.1.
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jan 8, 2024
CVE-2023-52213 on NVD →
Rate Star Review <= 1.5.1 - Reflected Cross-Site Scripting
medium
The Rate Star Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jan 3, 2024
CVE-2023-52213 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database