Extension WordPress
Vulnérabilités kk Star Ratings – Rate Post & Collect User Feedbacks
Cette page rassemble les failles publiées pour kk Star Ratings – Rate Post & Collect User Feedbacks, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de kk Star Ratings – Rate Post & Collect User Feedbacks
6 fiches
kk Star Ratings – Rate Post & Collect User Feedbacks <= 5.4.10 – Unauthenticated Arbitrary Shortcode Execution
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10. This is due to the software allowing users to…
*-5.4.10
5.4.10.2
20/12/2024
kk Star Ratings <= 5.4.5 – Race Condition to Multiple User Voting
The kk Star Ratings plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 5.4.5. This is due to insufficient controls and checks on a user voting. This makes it possible for…
*-5.4.5
5.4.6
06/11/2023
kk Star Ratings <= 5.4.5 – Missing Authorization
The kk Star Ratings plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on an unknown function in versions up to, and including, 5.4.5. This makes it possible for unauthenticated attackers…
*-5.4.5
5.4.6
25/10/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
3.0.0-5.4.4
5.4.5
18/07/2023
kk Star Ratings <= 5.4.3 – IP Spoofing to Protection Mechanism Bypass
The kk Star Ratings plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.4.3. This is due to the plugin prioritizing obtaining a visitor's IP address from a spoofable HTTP header over…
*-5.4.3
5.4.4
17/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 5.2.9)
5.2.9
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.