Thumbs Rating <= 5.0.0 - Race Condition

2023-04-28 00:00
thiennv

Strategic Overview

Status
Unpatched
Affected PluginThumbs Rating
Affected Version<= 5.0.0
CVSS5.3Medium
CVECVE-2022-45809
View all Thumbs Rating vulnerabilities

Vulnerability Overview

The Thumbs Rating plugin for WordPress is vulnerable to a race condition in versions up to, and including, 5.0.0. This is due to insufficient controls on resources being executed concurrently. The impact of this vulnerability is unknown, however, it may be possible to lose integrity of a post's votes if too many requests are made concurrently.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')) The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C