Cross Site Scripting Vulnerability in GamerZ WP-PostRatings Could Lead to Remote Code Execution
CVE-2011-10006
3.5LOW
Summary
A cross-site scripting vulnerability exists in the GamerZ WP-PostRatings plugin prior to version 1.65. The flaw resides in the wp-postratings.php file, allowing attackers to manipulate content to execute script code in the context of the user's browser session. This vulnerability can be exploited remotely, making it imperative for users of affected versions to promptly upgrade to version 1.65 to alleviate potential security risks associated with this issue.
Affected Version(s)
WP-PostRatings 1.0
WP-PostRatings 1.1
WP-PostRatings 1.2
References
CVSS V3.1
Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
VulDB GitHub Commit Analyzer