CVE-2024-13362
YASR – Yet Another Star Rating Plugin for WordPress
Minimum safe version
3.4.15
Update to 3.4.15 or later to address 15 fixable vulnerabilities
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2023-39305
WordPress Yet Another Stars Rating Plugin < 3.4.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-37867
CVE-2022-40699
Yet Another Stars Rating <= 1.8.6 - Unauthenticated PHP Object Injection
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Yet Another Stars Rating <= 1.8.6 - PHP Object Injection
WordPress Yet Another Stars Rating Plugin <= 0.9.0 - Blind SQL Injection
WordPress Yet Another Stars Rating plugin <= 1.8.6 - PHP Object Injection vulnerability
WordPress Yet Another Stars Rating plugin < 3.0.2 - Sensitive Information Disclosure vulnerability
WordPress Yet Another Stars Rating plugin < 3.0.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2015-9465
CVE-2022-23980