SQL Injection Vulnerability in Yet Another Stars Rating Plugin for WordPress
CVE-2015-9465
8.8HIGH
Summary
The Yet Another Stars Rating plugin for WordPress prior to version 0.9.1 is susceptible to SQL injection via the 'set_id' parameter in the yasr_get_multi_set_values_and_field function. This flaw allows attackers to manipulate the database query, potentially allowing them to retrieve, modify, or delete sensitive data. It is crucial for website administrators using affected versions of the plugin to apply updates promptly in order to protect against possible exploitation.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved