Vulnerability Details CVE-2021-24893
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 70.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-24893
-
cpe:2.3:a:stars_rating_project:stars_rating:-
-
cpe:2.3:a:stars_rating_project:stars_rating:1.0.0
-
cpe:2.3:a:stars_rating_project:stars_rating:1.1.0
-
cpe:2.3:a:stars_rating_project:stars_rating:1.2.0
-
cpe:2.3:a:stars_rating_project:stars_rating:1.3.0
-
cpe:2.3:a:stars_rating_project:stars_rating:1.3.1
-
cpe:2.3:a:stars_rating_project:stars_rating:2.0.0
-
cpe:2.3:a:stars_rating_project:stars_rating:3.0.0
-
cpe:2.3:a:stars_rating_project:stars_rating:3.1.0
-
cpe:2.3:a:stars_rating_project:stars_rating:3.2.0
-
cpe:2.3:a:stars_rating_project:stars_rating:3.3.0
-
cpe:2.3:a:stars_rating_project:stars_rating:3.4.0
-
cpe:2.3:a:stars_rating_project:stars_rating:3.5.0