PT-2024-12570 · Unknown · Kk Star Ratings

Mika

·

Published

2024-12-13

·

Updated

2024-12-16

·

CVE-2023-36528

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions KK Star Ratings versions 5.4.3 and earlier
Description The issue is related to a Missing Authorization vulnerability in the KK Star Ratings plugin, allowing rate manipulation via IP spoofing. This vulnerability exploits incorrectly configured access control security levels. To protect sites, updating to the latest version of the plugin is recommended.
Recommendations For KK Star Ratings versions 5.4.3 and earlier, update to the latest version of the plugin to secure the site against rate manipulation via IP spoofing. As a temporary workaround, consider restricting access to the plugin's rating functionality until the update is applied.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-36528

Affected Products

Kk Star Ratings