Description
WordPress Plugin Comment Rating is prone to an SQL injection and a security bypass weakness vulnerabilities. Exploiting these issues could allow an attacker to bypass certain security restrictions and submit multiple votes for a comment or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Comment Rating version 2.9.32 is vulnerable; other versions may also be affected.
Remediation
Disable the plugin
References
Related Vulnerabilities
CKEditor Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2021-26272)
WordPress Plugin WordPress Connect Cross-Site Scripting (2.0.3)
WordPress Plugin WordPress Gallery Cross-Site Scripting (1.0)
WordPress Plugin Glass Cross-Site Request Forgery (1.3.2)
WordPress Plugin Goolytics-Simple Google Analytics Cross-Site Scripting (1.1.1)