CVE · Medium

CVE-2022-40310 — Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-40310 Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.5 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Medium 4.3 < 3.3.5 3.3.5 2022-09-01

CVE-2022-40310

The Rate My Post plugin through version 3.3.4 contains a race condition vulnerability that allows attackers to arbitrarily increase or decrease vote counts. This flaw arises from improper handling of concurrent voting requests, enabling manipulation of ratings. The vulnerability affects all installations running version 3.3.4 and earlier, and users should upgrade to version 3.3.5 or later to remediate the issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.