SQL Injection Vulnerability in Yet Another Stars Rating Plugin for WordPress
CVE-2015-9465
8.8HIGH
What is CVE-2015-9465?
The Yet Another Stars Rating plugin for WordPress prior to version 0.9.1 is susceptible to SQL injection via the 'set_id' parameter in the yasr_get_multi_set_values_and_field function. This flaw allows attackers to manipulate the database query, potentially allowing them to retrieve, modify, or delete sensitive data. It is crucial for website administrators using affected versions of the plugin to apply updates promptly in order to protect against possible exploitation.