CVE-2021-24893

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/01/2022
Last modified:
30/08/2022

Description

The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:stars_rating_project:stars_rating:*:*:*:*:*:wordpress:*:* 3.5.1 (excluding)