Eklenti güvenlik geçmişi
GD Rating System güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) GD Rating System eklentisi için 6 açık kaydı bulunuyor; en yenisi 3 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 3 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 3.7.2.
- Toplam kayıt
- 6
- Kritik veya yüksek
- 3
- Oturumsuz istismar
- 3
- Son kayıt
- 3 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.7.1 ve öncesi · Oturum açmadan istismar edilebilir
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although the AJAX action requires a per-item nonce, that nonce is publicly emitted in the page's <script class="gdrts-rating-data"> JSON block on every page rendering the rating item, making it obtainable by any unauthenticated visitor and therefore not an authentication barrier.
Türkçe kayıt ve ne yapmalıSQL enjeksiyonu
Etkilenen sürümler: 3.7 ve öncesi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.
SQL enjeksiyonu
Etkilenen sürümler: 3.6.2 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.6.1 ve öncesi
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
yerel dosya dahil etme (LFI)
Etkilenen sürümler: 3.6 ve öncesi
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating System allows PHP Local File Inclusion.This issue affects GD Rating System: from n/a through 3.6.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 3.5 ve öncesi · Oturum açmadan istismar edilebilir
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Rating System: from n/a through 3.5.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.