CVE-2023-4642
kk Star Ratings < 5.4.6 - Rating Tampering via Race Condition
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.
El complemento kk Star Ratings de WordPress anterior a 5.4.6 no implementa operaciones atómicas, lo que permite a un usuario votar varias veces en una encuesta debido a una condición de ejecución.
The kk Star Ratings plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 5.4.5. This is due to insufficient controls and checks on a user voting. This makes it possible for unauthenticated attackers to provides ratings more than a single time.
KK Star Ratings versions prior to 5.4.6 suffer from rate tampering via a race condition vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-08-30 CVE Reserved
- 2023-11-06 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/6f481d34-6feb-4af2-914c-1f3288f69207 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kamalkhan Search vendor "Kamalkhan" | Kk Star Ratings Search vendor "Kamalkhan" for product "Kk Star Ratings" | < 5.4.6 Search vendor "Kamalkhan" for product "Kk Star Ratings" and version " < 5.4.6" | wordpress |
Affected
|