The kk Star Ratings plugin, which is used to add a rating system to WordPress websites, is at risk of being exploited by attackers. Versions of the plugin up to and including 5.4.3 are affected. It is possible to provide a header with a fake IP address, which will bypass a setting that should limit the number of votes from each individual. This means that votes could be cast multiple times from the same IP address.