vendor:
kk Star Ratings
by:
Mohammad Reza Omrani
4.1
CVSS
MEDIUM
Rating Tampering
362
CWE
Product Name: kk Star Ratings
Affected Version From: 5.4.2005
Affected Version To: 38812
Patch Exists: YES
Related CWE: CVE-2023-4642
CPE: a:kk-star-ratings_project:kk-star-ratings:5.4.5
Platforms Tested: Wordpress
2023
kk Star Ratings < 5.4.6 - Rating Manipulation via Race Condition
The kk Star Ratings plugin before version 5.4.6 in WordPress is vulnerable to a race condition that allows an attacker to manipulate ratings. By intercepting the rating submission request using tools like Burp and Turbo Intruder, an attacker can send multiple requests simultaneously to the server, resulting in unauthorized changes to the rating values displayed on the page.
Mitigation:
Update kk Star Ratings plugin to version 5.4.6 or newer to prevent exploitation of this vulnerability.