WordPress Yet Another Stars Rating Plugin <= 3.3.8 is vulnerable to Race Condition
CVE-2023-37867
8.1HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 30 November 2023
What is CVE-2023-37867?
The Yet Another Star Rating Plugin for WordPress is affected by a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. This flaw allows an attacker to exploit the time gap between verifying a required condition and subsequently using the result, potentially leading to unauthorized actions or data manipulation. This impacts all versions from n/a up to 3.3.8, posing security risks for WordPress sites utilizing this plugin.
Affected Version(s)
YASR – Yet Another Star Rating Plugin for WordPress <= 3.3.8