WordPress GD Star Rating Plugin 'votes' Parameter SQL Injection Vulnerability
19 Jul. 2012
Summary
The GD Star Rating plugin for WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Vulnerable Systems:
* Milan Petrovic GD Star Rating
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Vendor Status:
Currently, we are not aware of any vendor-supplied patches.