Description
The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 17 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-17T14:09:11.308Z
Reserved: 2021-01-14T15:03:46.870Z
Link: CVE-2021-25117
Updated: 2024-08-03T19:56:10.858Z
Status : Modified
Published: 2024-01-16T16:15:09.213
Modified: 2025-06-17T14:15:26.197
Link: CVE-2021-25117
No data.
OpenCVE Enrichment
No data.
Weaknesses