CVE Database /
CVE-2022-40310
CVE · Medium
CVE-2022-40310 — Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-40310
|
Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.5 |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
Medium
4.3
|
< 3.3.5
|
3.3.5 |
2022-09-01 |
—
|
CVE-2022-40310
The Rate My Post plugin through version 3.3.4 contains a race condition vulnerability that allows attackers to arbitrarily increase or decrease vote counts. This flaw arises from improper handling of concurrent voting requests, enabling manipulation of ratings. The vulnerability affects all installations running version 3.3.4 and earlier, and users should upgrade to version 3.3.5 or later to remediate the issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings