Beta

Report

Yet Another Stars Rating <= 3.4.3 is vulnerable to Broken Access Control vulnerability

Unauthenticated
Published
2023-11-26

The Yet Another Stars Rating plugin for WordPress is vulnerable to unauthorized modification of data due to a missing check on the init function in versions up to, and including, 3.4.3. This makes it possible for unauthenticated attackers to vote on private or nonexistent posts.

CVSS

Score:5.3

Severity:Medium

Version: 3.4.3

There is a patch available in v3.4.4 and we strongly recommend you update to this version as soon as possible.