Description
WordPress Plugin Comment Rating is prone to an SQL injection and a security bypass weakness vulnerabilities. Exploiting these issues could allow an attacker to bypass certain security restrictions and submit multiple votes for a comment or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Comment Rating version 2.9.32 is vulnerable; other versions may also be affected.
Remediation
Disable the plugin
References
Related Vulnerabilities
WordPress 4.7.x Possible SQL Injection Vulnerability (4.7 - 4.7.6)
WordPress Plugin Customize Feeds for Twitter Cross-Site Request Forgery (1.8.8)
WordPress Plugin Groundhogg-Marketing Automation & CRM for WordPress Remote Code Execution (1.3.4)
WordPress Plugin Duplicator-WordPress Migration SQL Injection (0.5.14)
WordPress Plugin WP Fastest Cache Arbitrary File Deletion (0.8.9.0)