Description
WordPress Plugin Comment Rating is prone to an SQL injection and a security bypass weakness vulnerabilities. Exploiting these issues could allow an attacker to bypass certain security restrictions and submit multiple votes for a comment or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Comment Rating version 2.9.32 is vulnerable; other versions may also be affected.
Remediation
Disable the plugin
References
Related Vulnerabilities
WordPress Plugin eShop Code Injection (6.3.11)
WebLogic CVE-2018-3250 Vulnerability (CVE-2018-3250)
Sqlite Out-of-bounds Read Vulnerability (CVE-2019-8457)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-1692)
WordPress Plugin Easy Preloader Cross-Site Scripting (1.0.0)