Description
WordPress Plugin Comment Rating is prone to an SQL injection and a security bypass weakness vulnerabilities. Exploiting these issues could allow an attacker to bypass certain security restrictions and submit multiple votes for a comment or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Comment Rating version 2.9.32 is vulnerable; other versions may also be affected.
Remediation
Disable the plugin
References
Related Vulnerabilities
Moodle Credentials Management Errors Vulnerability (CVE-2009-4304)
WordPress Plugin YITH WooCommerce Zoom Magnifier Security Bypass (1.3.11)
MySQL CVE-2021-2030 Vulnerability (CVE-2021-2030)
Ruby Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-31810)
WordPress Plugin Post Recommendations for WordPress 'api.php' Remote File Include (1.1.2)