Description
WordPress Plugin Rate my Post-WP Rating System is prone to multiple vulnerabilities, including security bypass and cross-site request forgery vulnerabilities. Exploiting these issues could allow an attacker to perform otherwise restricted actions and subsequently increment/decrement the number of votes via race condition, or to perform certain administrative actions and gain unauthorized access to the affected application. WordPress Plugin Rate my Post-WP Rating System version 3.3.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.5 or latest
References
https://wpscan.com/vulnerability/9980e253-9134-44aa-aaab-ec669a065bc8
https://wpscan.com/vulnerability/cf975eef-4262-42af-9474-2a9cd5e34251
https://plugins.svn.wordpress.org/rate-my-post/trunk/readme.txt
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2002-0072)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1432)
WordPress 5.3.x Multiple Vulnerabilities (5.3 - 5.3.3)
ownCloud Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-2044)
WordPress Plugin Captcha by BestWebSoft Security Bypass (4.0.6)