WPHizmet

Eklenti güvenlik geçmişi

GD Rating System güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) GD Rating System eklentisi için 6 açık kaydı bulunuyor; en yenisi 3 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 3 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 3.7.2.

Toplam kayıt
6
Kritik veya yüksek
3
Oturumsuz istismar
3
Son kayıt
3 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-93430Yüksek · 7,23 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.7.1 ve öncesi · Oturum açmadan istismar edilebilir

    The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although the AJAX action requires a per-item nonce, that nonce is publicly emitted in the page's <script class="gdrts-rating-data"> JSON block on every page rendering the rating item, making it obtainable by any unauthenticated visitor and therefore not an authentication barrier.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-57771Yüksek · 8,513 Temmuz 2026

    SQL enjeksiyonu

    Etkilenen sürümler: 3.7 ve öncesi

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.

  • CVE-2026-42639Kritik · 9,316 Haziran 2026

    SQL enjeksiyonu

    Etkilenen sürümler: 3.6.2 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

  • CVE-2024-11198Orta · 6,419 Kasım 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.6.1 ve öncesi

    The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2024-38709Orta · 5,312 Temmuz 2024

    yerel dosya dahil etme (LFI)

    Etkilenen sürümler: 3.6 ve öncesi

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating System allows PHP Local File Inclusion.This issue affects GD Rating System: from n/a through 3.6.

  • CVE-2024-25093Orta · 6,129 Şubat 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.5 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Rating System: from n/a through 3.5.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.