CVE-2023-37867 LOW

CVE-2023-37867: WordPress Yet Another Stars Rating Plugin <= 3.3.8 is vulnerable to Race Condition

Vendor Yetanotherstarsrating.com
Product YASR – Yet Another Star Rating Plugin for WordPress
Weakness CWE-367
Published November 30, 2023
Last update April 28, 2026

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8.

Explanation of Vulnerability in Simple Terms

02Summary

YASR – Yet Another Star Rating Plugin for WordPress versions up to 3.3.8 contains a time-of-check-time-of-use (TOCTOU) race condition that allows an attacker to modify rating data. The vulnerability requires specific timing and network conditions to exploit but does not require authentication. Site administrators should update to a version newer than 3.3.8.

What an attacker can do

03Attacker Capabilities

Modify star ratings or rating data through a race condition exploit.

Potential impact on your site

04Site Impact

Star ratings on your site could be altered by an attacker without authentication, affecting review integrity.

Conditions required to exploit

05Prerequisites

Network access; attacker must exploit a timing window between data validation and storage.

Key dates

06Disclosure timeline

November 30, 2023 CVE published
April 28, 2026 Record updated