What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.
Explanation of Vulnerability in Simple Terms
Rate my Post – WP Rating System versions up to 3.4.1 contain an authorization flaw that allows authenticated users to modify rating data they should not have access to. An attacker with a low-privilege account can alter ratings or related post metadata through improper access controls. The vulnerability requires a valid WordPress user account but no additional user interaction.
What an attacker can do
Modify ratings or post data belonging to other users or posts without proper authorization.
Potential impact on your site
Ratings and post metadata can be tampered with by any logged-in user, compromising the integrity of your rating system.
Conditions required to exploit
Attacker must have a valid WordPress user account with at least subscriber-level access.
Key dates
External resources
Related vulnerabilities