Functionality Misuse via Missing Authorization
CVE-2023-32127
5.3MEDIUM
What is CVE-2023-32127?
A missing authorization vulnerability exists in the Multi Rating plugin developed by Daniel Powney, allowing unauthorized users to exploit the functionality of the plugin. This can lead to misuse, including arbitrary rating value changes. The issue affects versions up to 5.0.6 and highlights the importance of proper user role management and access controls to mitigate such risks.
Affected Version(s)
Multi Rating <= 5.0.6