Vulnerability Description
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Implecode | Reviews Plus | < 1.2.14 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2618234PatchThird Party Advisory
- https://wpscan.com/vulnerability/79bb5acb-ea56-41a9-83a1-28a181ae41e2ExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2618234PatchThird Party Advisory
- https://wpscan.com/vulnerability/79bb5acb-ea56-41a9-83a1-28a181ae41e2ExploitThird Party Advisory
FAQ
What is CVE-2021-24894?
CVE-2021-24894 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated use...
How severe is CVE-2021-24894?
CVE-2021-24894 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24894?
Check the references section above for vendor advisories and patch information. Affected products include: Implecode Reviews Plus.