Yasr – Yet Another Stars Rating

Yasr - Yet Another Stars Rating is a plugin that allows users to add SEO-friendly user-generated reviews and testimonials to their website posts, pages, and CPT. The plugin can be used with both classic and new Gutenberg editors, and users can add overall ratings and visitor votes to their content. Additionally, the plugin offers multi-set options for scoring different aspects of each review and migration tools for users to switch from other rating plugins.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Input validation vulnerability in Yasr – Yet Another Stars Rating 2.9.9

    Fixed

    A security issue has been found in the Yasr - Yet Another Stars Rating WordPress plugin

    Read More
  • Input validation vulnerability in Yasr – Yet Another Stars Rating 3.1.2

    Fixed

    The Yet Another Stars Rating plugin for WordPress is not secure in versions up to 3.1.2. This means that someone with a subscriber-level account can put malicious code into a website. When someone vis...

    Read More
  • Output validation vulnerability in Yasr – Yet Another Stars Rating 1.8.6

    Fixed

    The Yet Another Stars Rating plugin for WordPress is vulnerable to a type of cyber attack known as PHP Object Injection. This type of attack can happen if someone is using an older version of the plu...

    Read More
  • Input validation vulnerability in Yasr – Yet Another Stars Rating 0.9.1

    Fixed

    A plugin for WordPress called Yet Another Stars Rating (YASR) had a security issue in versions before 0.9.1. This issue allowed attackers to inject malicious code into the system by using the “set_i...

    Read More
  • Access violation vulnerability in Freemius SDK (620 components affected)

    Fixed

    Freemius, a software development kit used by hundreds of WordPress plugin and theme developers, had a security vulnerability in its older versions (up to and including 2.4.2). This vulnerability could...

    Read More