Reviews Plus < 1.2.14 - Denial of Service
Strategic Overview
< 1.2.14CVE-2021-24894Vulnerability Overview
The Reviews Plus plugin for WordPress is vulnerable to Denial of Service in versions before 1.2.14. This is due to an unknown part of the file post/page of the component Rating Submission Handler. The manipulation with an unknown input leads to a denial of service vulnerability. This makes it possible for authentication attackers, a authentication is necessary for exploitation to cause a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page.
Technical Analysis
REMEDIATION: Update to version 1.2.15, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C