CVE-2021-24894: Reviews Plus < 1.2.14 - Subscriber+ Reviews DoS
Published Nov 23, 2021
·Updated
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page
Affected Software
1 affected component
impleCode Reviews Plus Wordpress<1.2.14
Remediation
Patch Available
Event History
Nov 23, 2021
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24894?
CVE-2021-24894 refers to a vulnerability in the Reviews Plus WordPress plugin before version 1.2.14.
2
What is the severity of CVE-2021-24894?
The severity of CVE-2021-24894 is medium with a CVSS score of 6.5.
3
How does CVE-2021-24894 affect the Reviews Plus plugin?
CVE-2021-24894 allows submission of long integer ratings in the review section, causing a Denial of Service when displayed on the post/page.
4
Which version of the Reviews Plus plugin is affected by CVE-2021-24894?
The Reviews Plus plugin before version 1.2.14 is affected by CVE-2021-24894.
5
How can I fix CVE-2021-24894?
To fix CVE-2021-24894, update the Reviews Plus plugin to version 1.2.14 or newer.