WP-PostRatings <= 1.91.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP-PostRatings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google rich text snippets in versions up to, and including, 1.91.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a...
- CVSS:
- 6.4
- Affected:
- up to 1.91.1
- Fixed in:
- 1.91.2
- Disclosed:
- Aug 1, 2024
CVE-2024-39659 on NVD →
WP-PostRatings [wp-postratings] < 1.91.2
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Stored XSS.This issue affects WP-PostRatings: from n/a through 1.91.1.
- Affected:
- up to 1.91.2
- Fixed in:
- 1.91.2
- Disclosed:
- Aug 1, 2024
CVE-2024-39659 on NVD →
WP-PostRatings [wp-postratings] < 1.91.1
unknown
[en] Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.
- Affected:
- up to 1.91.1
- Fixed in:
- 1.91.1
- Disclosed:
- Jun 4, 2024
CVE-2023-40332 on NVD →
WP-PostRatings [wp-postratings] < 1.65
unknown
[en] A vulnerability was found in GamerZ WP-PostRatings up to 1.64. It has been classified as problematic. This affects an unknown part of the file wp-postratings.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.65 is able to address this issue....
- Affected:
- up to 1.65
- Fixed in:
- 1.65
- Disclosed:
- Apr 8, 2024
CVE-2011-10006 on NVD →
WP-PostRatings [wp-postratings] < 1.86.1
unknown
[en] The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable w...
- Affected:
- up to 1.86.1
- Fixed in:
- 1.86.1
- Disclosed:
- Jan 16, 2024
CVE-2021-25117 on NVD →
WP-PostRatings <= 1.91 - IP Spoofing
medium
The WP-PostRatings plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.91. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a dif...
- CVSS:
- 5.3
- Affected:
- up to 1.91
- Fixed in:
- 1.91.1
- Disclosed:
- Aug 16, 2023
CVE-2023-40332 on NVD →
WP-PostRatings [wp-postratings] < 1.90
unknown
[en] Rating increase/decrease via race condition in Lester 'GaMerZ' Chan WP-PostRatings plugin <= 1.89 at WordPress.
- Affected:
- up to 1.90
- Fixed in:
- 1.90
- Disclosed:
- Sep 9, 2022
CVE-2022-36422 on NVD →
WP-PostRatings <= 1.89 - Race Condition
medium
The WP-PostRatings plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 1.89. This can lead to unpredictable post rating changes when certain conditions are met.
- CVSS:
- 4.3
- Affected:
- up to 1.89
- Fixed in:
- 1.90
- Disclosed:
- Aug 31, 2022
CVE-2022-36422 on NVD →
WP-PostRatings <= 1.86 - Cross-Site Scripting
medium
The WP-PostRatings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postratings_image’ parameter in versions up to, and including, 1.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 5.5
- Affected:
- up to 1.86
- Fixed in:
- 1.86.1
- Disclosed:
- Dec 24, 2020
CVE-2021-25117 on NVD →
WP-PostRatings [wp-postratings] < 1.86.1
unknown
Stored Cross-Site Scripting (XSS) vulnerability found by Park Won Seok in WordPress WP-PostRatings plugin (versions <= 1.86).
- Affected:
- up to 1.86.1
- Fixed in:
- 1.86.1
- Disclosed:
- Dec 24, 2020
WP-PostRatings [wp-postratings] < 1.86.1
unknown
The WP-PostRatings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postratings_image’ parameter in versions up to, and including, 1.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- Affected:
- up to 1.86.1
- Fixed in:
- 1.86.1
- Disclosed:
- Dec 24, 2020
WP-PostRatings [wp-postratings] < 1.62
unknown
[en] SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions before 1.62 for WordPress allows remote authenticated users with the Author role to execute arbitrary SQL commands via the id attribute of the ratings shortcode when creating a post. NOTE: some o...
- Affected:
- up to 1.62
- Fixed in:
- 1.62
- Disclosed:
- Nov 30, 2011
CVE-2011-4646 on NVD →
WP-PostRatings <= 1.61 - SQL Injection
high
SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions before 1.62 for WordPress allows remote authenticated users with the Author role to execute arbitrary SQL commands via the id attribute of the ratings shortcode when creating a post. NOTE: some of thes...
- CVSS:
- 8.8
- Affected:
- up to 1.61
- Fixed in:
- 1.62
- Disclosed:
- Oct 6, 2011
CVE-2011-4646 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database