Description
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Published: 2026-08-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress allows an attacker to pass an arbitrary payload to the do_shortcode function without validation, enabling the execution of any shortcode. This flaw can be leveraged by unauthenticated users to run custom code on the site, potentially leading to a full remote code execution scenario on the hosting environment.

Affected Systems

Any WordPress site that has the kk Star Ratings plugin installed with a version up to and including 5.4.10.3 is affected. The vulnerability exists in all releases of the plugin prior to 5.4.10.4 and is documented in the plugin’s source code where the payload parameter is handled.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation cannot be quantified from the available data. The vulnerability is listed as unauthenticated, implying that the attack vector is via a publicly reachable AJAX endpoint that processes the payload without checking the user’s identity. Because it is not included in the CISA KEV catalog, there is no evidence of known exploitation yet, but the potential for arbitrary code execution makes it a high‑risk target for automated exploitation attempts if a newer unpatched version is not deployed.

Generated by OpenCVE AI on August 22, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kk Star Ratings plugin to the latest version that removes the payload vulnerability
  • If an upgrade is not immediately possible, disable or delete the kk Star Ratings plugin to eliminate the attack surface
  • Maintain all other WordPress components and plugins at their latest secure releases and monitor the site for suspicious activity

Generated by OpenCVE AI on August 22, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 23 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Properfraction
Properfraction kk Star Ratings – Rate Post & Collect User Feedbacks
Wordpress
Wordpress wordpress
Vendors & Products Properfraction
Properfraction kk Star Ratings – Rate Post & Collect User Feedbacks
Wordpress
Wordpress wordpress

Sat, 22 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Title kk Star Ratings <= 5.4.10.3 - Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Properfraction Kk Star Ratings – Rate Post & Collect User Feedbacks
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-26T17:49:29.945Z

Reserved: 2026-03-02T04:06:09.192Z

Link: CVE-2026-3424

cve-icon Vulnrichment

Updated: 2026-08-26T17:49:21.357Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T12:16:24.677

Modified: 2026-08-26T18:16:31.763

Link: CVE-2026-3424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-23T16:40:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')