CVE-2021-24894
Reviews Plus < 1.2.14 - Subscriber+ Reviews DoS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page
El plugin Reviews Plus de WordPress versiones anteriores a 1.2.14, no comprueba la valoración enviada, permitiendo el envío de enteros largos, causando una Denegación de Servicio en la sección de valoraciones cuando un usuario autenticado envía dicha valoración y las valoraciones están configuradas para ser mostradas en el post/página
The Reviews Plus plugin for WordPress is vulnerable to Denial of Service in versions before 1.2.14. This is due to an unknown part of the file post/page of the component Rating Submission Handler. The manipulation with an unknown input leads to a denial of service vulnerability. This makes it possible for authentication attackers, a authentication is necessary for exploitation to cause a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-10-25 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-191: Integer Underflow (Wrap or Wraparound)
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/79bb5acb-ea56-41a9-83a1-28a181ae41e2 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2618234 | 2022-10-25 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Implecode Search vendor "Implecode" | Reviews Plus Search vendor "Implecode" for product "Reviews Plus" | < 1.2.14 Search vendor "Implecode" for product "Reviews Plus" and version " < 1.2.14" | wordpress |
Affected
|