Rating-Widget: Star Review System

RatingWidget offers a GDPR-compliant Five Star Review System for WordPress websites, with user-friendly ratings for posts, pages, comments, WooCommerce, BuddyPress and bbPress forums. The system includes ratings for custom post types and author reviews. The company has introduced two client-side methods to help with cookies consent opt-in/out logic, and no longer stores IP addresses, instead using anonymised IPs. Device ID cookies are also no longer created for EU visitors.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Access violation vulnerability in Rating-Widget: Star Review System 2.9.0

    Fixed

    The Rating Widget plugin for WordPress is potentially unsafe in versions up to and including 2.8. There is a security risk that allows unauthenticated attackers to access sensitive information such a...

    Read More
  • Input validation vulnerability in Rating-Widget: Star Review System 3.1.9

    Fixed

    The Rating Widget plugin for WordPress has a security flaw that is present in versions up to 3.1.9. If someone with contributor-level or higher access has permission to use certain shortcodes

    Read More
  • Access violation vulnerability in Freemius SDK (620 components affected)

    Fixed

    Freemius, a software development kit used by hundreds of WordPress plugin and theme developers, had a security vulnerability in its older versions (up to and including 2.4.2). This vulnerability could...

    Read More