Starfish Review Generation & Marketing for WordPress <= 3.1.19 - Authenticated (Subscriber+) Arbitrary Options Update via srm_restore_options_defaults
Starfish Review Generation & Marketing for WordPress
Minimum safe version
3.1.20
Update to 3.1.20 or later to address 9 fixable vulnerabilities
CVE-2025-39533
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Starfish Review Generation & Marketing for WordPress Plugin < 3.1.1 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress Starfish Review Generation & Marketing for WordPress plugin <= 3.0.25 - Sensitive Information Disclosure vulnerability
WordPress Starfish Review Generation & Marketing for WordPress plugin <= 3.0.25 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability