PLUGIN SECURITY
Is Rate My Post safe?
Add Star Rating to WordPress posts & pages, collect feedbacks from users and improve website SEO with Schema markup for Rich Snippets.
What this plugin does
- Slug:
rate-my-post - Author: properfraction
- 20000+ active installs
- 94/100 rating (158 reviews on wordpress.org)
- 721724 all-time downloads
- On WordPress.org since 2018-03-01
post ratingRate Pagerate postrating systemstar rating
Maintenance status
- Latest known version: 4.5.2
- Last updated: 2026-08-20 4:44pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
Known vulnerabilities
7 known CVEs on file for Rate My Post. Reported between 2022 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-12309 | Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 4.2.5 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 4.2.5 | 4.2.5 | 2024-12-12 | ✓ fixed in latest |
| CVE-2024-32823 | Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.4.5 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 3.4.5 | 3.4.5 | 2024-04-22 | ✓ fixed in latest |
| CVE-2023-51667 | Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.4.3 | Authentication Bypass by Spoofing | Medium 5.3 | < 3.4.3 | 3.4.3 | 2023-12-27 | ✓ fixed in latest |
| CVE-2023-49765 | Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.4.2 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 3.4.2 | 3.4.2 | 2023-08-11 | ✓ fixed in latest |
| CVE-2022-4673 | Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.3.9 | 3.3.9 | 2022-12-27 | ✓ fixed in latest |
| CVE-2022-40671 | Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.5 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 3.3.5 | 3.3.5 | 2022-09-14 | ✓ fixed in latest |
| CVE-2022-40310 | Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 3.3.5 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | Medium 4.3 | < 3.3.5 | 3.3.5 | 2022-09-01 | ✓ fixed in latest |
How to fix it
Keep Rate My Post updated — 4.5.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.