QID 150550
Date Published: 2022-07-29
QID 150550: WordPress Rating by BestWebSoft Plugin: Denial of Service Vulnerability (CVE-2021-25121)
Rating by BestWebSoft is a simple and powerful plugin, that can add a five-star rating to your website posts, widgets, and pages.
The plugin does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating.
Affected Versions:
WordPress Rating by BestWebSoft Plugin before 1.6
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of the vulnerability can allow an attacker to trigger a Denial of Service attack.
Solution
Customers are advised to upgrade to Rating by BestWebSoft 1.6 or later version to remediate this vulnerability. For more information regarding this vulnerability please refer WPScan Security Advisory
Vendor References
CVEs related to QID 150550
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WPScan |
|
||
| WPScan |
|