Description
WordPress Plugin Comment Rating is prone to an SQL injection and a security bypass weakness vulnerabilities. Exploiting these issues could allow an attacker to bypass certain security restrictions and submit multiple votes for a comment or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Comment Rating version 2.9.32 is vulnerable; other versions may also be affected.
Remediation
Disable the plugin
References
Related Vulnerabilities
Envoy mishandles dropped and truncated datagrams Issue (CVE-2020-35471)
Plone CMS CVE-2017-1000483 Vulnerability (CVE-2017-1000483)
Joomla Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2021-26038)
Joomla! Core 3.x.x Security Bypass (3.0.0 - 3.9.24)
WordPress Plugin ToolBar to Share Cross-Site Request Forgery (2.0)