Description
WordPress Plugin Rate my Post-WP Rating System is prone to multiple vulnerabilities, including security bypass and cross-site request forgery vulnerabilities. Exploiting these issues could allow an attacker to perform otherwise restricted actions and subsequently increment/decrement the number of votes via race condition, or to perform certain administrative actions and gain unauthorized access to the affected application. WordPress Plugin Rate my Post-WP Rating System version 3.3.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.5 or latest
References
https://wpscan.com/vulnerability/9980e253-9134-44aa-aaab-ec669a065bc8
https://wpscan.com/vulnerability/cf975eef-4262-42af-9474-2a9cd5e34251
https://plugins.svn.wordpress.org/rate-my-post/trunk/readme.txt
Related Vulnerabilities
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-3129)
ownCloud Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-2051)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-7848)
Oracle Database Server CVE-2011-0785 Vulnerability (CVE-2011-0785)
Werkzeug WSGI Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-49767)