What the vulnerability does
01Description
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8.
Explanation of Vulnerability in Simple Terms
02Summary
YASR – Yet Another Star Rating Plugin for WordPress versions up to 3.3.8 contains a time-of-check-time-of-use (TOCTOU) race condition that allows an attacker to modify rating data. The vulnerability requires specific timing and network conditions to exploit but does not require authentication. Site administrators should update to a version newer than 3.3.8.
What an attacker can do
03Attacker Capabilities
Modify star ratings or rating data through a race condition exploit.
Potential impact on your site
04Site Impact
Star ratings on your site could be altered by an attacker without authentication, affecting review integrity.
Conditions required to exploit
05Prerequisites
Network access; attacker must exploit a timing window between data validation and storage.
Key dates
06Disclosure timeline
November 30, 2023
CVE published
April 28, 2026
Record updated