CVE-2023-49765 MEDIUM

CVE-2023-49765: WordPress Rate my Post – WP Rating System Plugin <= 3.4.1 is vulnerable to Insecure Direct Object References (IDOR)

Vendor Blaz K.
Product Rate my Post – WP Rating System
Weakness CWE-639 · IDOR
Published December 21, 2023
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.

Explanation of Vulnerability in Simple Terms

02Summary

Rate my Post – WP Rating System versions up to 3.4.1 contain an authorization flaw that allows authenticated users to modify rating data they should not have access to. An attacker with a low-privilege account can alter ratings or related post metadata through improper access controls. The vulnerability requires a valid WordPress user account but no additional user interaction.

What an attacker can do

03Attacker Capabilities

Modify ratings or post data belonging to other users or posts without proper authorization.

Potential impact on your site

04Site Impact

Ratings and post metadata can be tampered with by any logged-in user, compromising the integrity of your rating system.

Conditions required to exploit

05Prerequisites

Attacker must have a valid WordPress user account with at least subscriber-level access.

Key dates

06Disclosure timeline

December 21, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE