CVE-2021-24894

CVE-2021-24894: Reviews Plus < 1.2.14 - Subscriber+ Reviews DoS

Vendor Unknown
Product Reviews Plus
Weakness CWE-191
Published November 23, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page

Key dates

02Disclosure timeline

November 23, 2021 CVE published
August 3, 2024 Record updated