CVE-2023-36528: WordPress kk Star Ratings plugin <= 5.4.3 - Rate Manipulation due to IP Spoofing Vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in properfraction kk Star Ratings kk-star-ratings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects kk Star Ratings: from n/a through <= 5.4.3.
Affected Software
1 affected component
properfraction kk Star Ratings<=5.4.3
Remediation
Information
Update the WordPress kk Star Ratings plugin to the latest available version (at least 5.4.4).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-36528?
CVE-2023-36528 is considered a high severity vulnerability due to its potential to allow unauthorized rate manipulation.
2
How do I fix CVE-2023-36528?
To fix CVE-2023-36528, update the kk Star Ratings plugin to version 5.4.4 or later.
3
What impact does CVE-2023-36528 have on my website?
CVE-2023-36528 can lead to manipulated ratings on your website, undermining the integrity of the rating system.
4
Who is affected by CVE-2023-36528?
CVE-2023-36528 affects users of the kk Star Ratings plugin version 5.4.3 and earlier.
5
What is the cause of CVE-2023-36528?
The cause of CVE-2023-36528 is improper access control that allows IP spoofing, leading to rate manipulation.