Yet Another Stars Rating <= 3.3.8 - Missing Authorization to Vote Tampering
2023-07-10 00:00
Abdi PranataStrategic Overview
StatusPatched in 3.3.9
Affected PluginYASR – Yet Another Star Rating Plugin for WordPress
Affected Version
<= 3.3.8CVSS5.3Medium
CVE
CVE-2023-37867Vulnerability Overview
The Yet Another Stars Rating plugin for WordPress is vulnerable to vote tampering in versions up to, and including, 3.3.8. This vulnerability can be utilized by unauthenticated users to vote repeatedly.
Technical Analysis
REMEDIATION: Update to version 3.3.9, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C