kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings · plugin
Known security vulnerabilities for kk Star Ratings – Rate Post & Collect User Feedbacks. Find out in seconds which version runs on your site with WP Lens.
4 known vulnerabilities
4 exploitable without logging in · latest Aug 22, 2026
Listed on wordpress.org · latest 5.4.10.5 · last updated Aug 20, 2026 · 70K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- High 7.3
CVE-2024-11977unauthenticated≤ 5.4.10
kk Star Ratings – Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution
- Medium 5.3
CVE-2026-3424unauthenticated≤ 5.4.10.3
kk Star Ratings <= 5.4.10.3 - Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter
- Medium 5.3
CVE-2023-46639unauthenticated≤ 5.4.5
WordPress kk Star Ratings plugin <= 5.4.5 - Broken Access Control vulnerability
- Medium 5.3
CVE-2023-36528unauthenticated≤ 5.4.3
WordPress kk Star Ratings plugin <= 5.4.3 - Rate Manipulation due to IP Spoofing Vulnerability
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).