vendor:
kk Star Ratings
by:
Mohammad Reza Omrani
4.1
CVSS
MEDIUM
Rating Tampering
362
CWE
Product Name: kk Star Ratings
Affected Version From: 5.4.2005
Affected Version To: 5.4.2006
Patch Exists: YES
Related CWE: CVE-2023-4642
CPE: a:kk-star-ratings_project:kk-star-ratings:5.4.5
Platforms Tested: Wordpress
2023
kk Star Ratings < 5.4.6 - Rating Tampering via Race Condition
The kk Star Ratings plugin before version 5.4.6 for WordPress allows attackers to tamper with ratings via a race condition. By intercepting the rating submission request using tools like Burp and Turbo Intruder, an attacker can manipulate the connection header and send multiple requests simultaneously to alter the total rates displayed on the page.
Mitigation:
Update to version 5.4.6 or later of the kk Star Ratings plugin to prevent this vulnerability. Additionally, monitor and rate limit requests to the rating submission endpoint to detect and mitigate potential tampering.