Extension WordPress
Vulnérabilités Rate My Post – Star Rating Plugin by FeedbackWP
Cette page rassemble les failles publiées pour Rate My Post – Star Rating Plugin by FeedbackWP, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Rate My Post – Star Rating Plugin by FeedbackWP
7 fiches
Rate My Post – Star Rating Plugin by FeedbackWP <= 4.2.4 – Unauthenticated Voting On Scheduled Posts
The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.4 via the get_post_status() due to missing validation on a user…
*-4.2.4
4.2.5
12/12/2024
Rate My Post – Star Rating Plugin by FeedbackWP <= 3.4.4 – Insecure Direct Object Reference
The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.4 due to missing validation on a user controlled key. This…
*-3.4.4
3.4.5
22/04/2024
Rate my Post – WP Rating System <= 3.4.2 – IP Address Spoofing
The Rate my Post – WP Rating System plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.4.2 due to insufficient IP address validation and use of user-supplied HTTP headers as…
*-3.4.2
3.4.3
27/12/2023
Rate my Post – WP Rating System <= 3.4.1 – Insecure Direct Object Reference
The Rate my Post – WP Rating System plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.4.1 due to missing validation on a user controlled key. This can allow users…
[*, 3.4.2)
3.4.2
11/08/2023
Rate my Post – WP Rating System <= 3.3.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Rate my Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-3.3.8
3.3.9
27/12/2022
Rate my Post – WP Rating System <= 3.3.4 – Cross-Site Request Forgery
The Rate my Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.4. This is due to missing or incorrect nonce validation on the has_valid_nonce function. This makes it possible for…
*-3.3.4
3.3.5
14/09/2022
Rate my Post – WP Rating System <= 3.3.4 – Race Condition
The Rate my Post plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 3.3.4. This can lead to unpredictable post rating changes when certain conditions are met.
*-3.3.4
3.3.5
01/09/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.