VendorsLester Chanwp-postratingsall versions
Vulnerabilities

Lester Chan Lester 'GaMerZ' Chan WP-PostRatings

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-40332
WordPress WP-PostRatings plugin <= 1.91 - Rating limit Bypass vulnerability
Published 2024-06-04 · Analyzed
9.8EPSS 0.004
CVE-2024-39659
WordPress WP-PostRatings plugin <= 1.91.1 - Cross Site Scripting (XSS) vulnerability
Published 2024-08-01 · Analyzed
6.5EPSS 0.003
CVE-2011-10006
GamerZ WP-PostRatings wp-postratings.php cross site scripting
Published 2024-04-08 · Analyzed
6.1EPSS 0.004
CVE-2011-4646
SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions before 1.62 for WordPress allows remote authenticated users with the Author role to execute arbitrary SQL commands via the id attribute of the ratings shortcode when creating a post. NOTE: some of these details are obtained from third party information.
Published 2011-11-30 · Modified
6.0EPSS 0.015
CVE-2021-25117
WP Postratings < 1.86.1 - Admin+ Stored Cross-Site Scripting
Published 2024-01-16 · Modified
4.8EPSS 0.002