← WordPress Vulnerabilities
WordPress security by component

Yet Another Stars Rating

Yet Another Stars Rating is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Dec 13, 2024; the highest CVE/CNA score is 8.8.

Plugin slug: yet-another-stars-rating

CVE-2023-39305: Yet Another Stars Rating: A security weakness

Yet Another Stars Rating is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedDec 13, 2024
Safe version guidanceSee mitigation notes
Safe version
Dec 13, 2024 CVE-2023-39305
Yet Another Stars Rating: A security weakness
Yet Another Stars Rating is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 30, 2023 CVE-2023-37867
YASR – Yet Another Star Rating Plugin for WordPress: A security weakness
YASR – Yet Another Star Rating Plugin for WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.7
NVD8.1
Mar 16, 2023 CVE-2022-40699
Yet Another Stars Rating: Cross-site scripting
Yet Another Stars Rating is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD6.1
Feb 04, 2022 CVE-2022-23980
Yet Another Stars Rating: Cross-site scripting
Yet Another Stars Rating is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVD6.1
Oct 10, 2019 CVE-2015-9465
Yet Another Stars Rating: SQL injection
Yet Another Stars Rating is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8