Beta

Report

kk Star Ratings <= 5.4.3 is vulnerable to Rate Manipulation due to IP Spoofing Vulnerability

Unauthenticated
Published
2023-07-16

The kk Star Ratings plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.4.3. This is due to the plugin prioritizing obtaining a visitor's IP address from a spoofable HTTP header over PHP's REMOTE_ADDR. Attackers can supply a header with with a different IP Address that can be used to bypass the 'Unique votes (based on IP Address)' setting.

CVSS

Score:5.3

Severity:Medium

Version: 5.4.3

There is a patch available in v5.4.4 and we strongly recommend you update to this version as soon as possible.