Reviews Plus < 1.2.14 - Denial of Service

2021-10-25 00:00
Drew Jones

Strategic Overview

Status
Patched in 1.2.15
Affected PluginReviews Plus
Affected Version< 1.2.14
CVSS6.5Medium
CVECVE-2021-24894
View all Reviews Plus vulnerabilities

Vulnerability Overview

The Reviews Plus plugin for WordPress is vulnerable to Denial of Service in versions before 1.2.14. This is due to an unknown part of the file post/page of the component Rating Submission Handler. The manipulation with an unknown input leads to a denial of service vulnerability. This makes it possible for authentication attackers, a authentication is necessary for exploitation to cause a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page.

Technical Analysis

REMEDIATION: Update to version 1.2.15, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C