← back
CVE-2021-24893

Stars Rating < 3.5.1 - Comments Denial of Service

EPSS 1.6%CWE-400
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
03 Jan 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.
Affected products
Unknown · Stars Rating

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →