Vulnerability Description
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stars Rating Project | Stars Rating | < 3.5.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/05d3af69-20b4-499a-8322-2b53674d6a58ExploitThird Party Advisory
- https://wpscan.com/vulnerability/05d3af69-20b4-499a-8322-2b53674d6a58ExploitThird Party Advisory
FAQ
What is CVE-2021-24893?
CVE-2021-24893 is a vulnerability with a CVSS score of 7.5 (HIGH). The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dash...
How severe is CVE-2021-24893?
CVE-2021-24893 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24893?
Check the references section above for vendor advisories and patch information. Affected products include: Stars Rating Project Stars Rating.