Description
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Published: 2026-08-22
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress allows an attacker to pass an arbitrary payload to the do_shortcode function without validation, enabling the execution of any shortcode. This flaw can be leveraged by unauthenticated users to run custom code on the site, potentially leading to a full remote code execution scenario on the hosting environment.

Affected Systems

Any WordPress site that has the kk Star Ratings plugin installed with a version up to and including 5.4.10.3 is affected. The vulnerability exists in all releases of the plugin prior to 5.4.10.4 and is documented in the plugin’s source code where the payload parameter is handled.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation cannot be quantified from the available data. The vulnerability is listed as unauthenticated, implying that the attack vector is via a publicly reachable AJAX endpoint that processes the payload without checking the user’s identity. Because it is not included in the CISA KEV catalog, there is no evidence of known exploitation yet, but the potential for arbitrary code execution makes it a high‑risk target for automated exploitation attempts if a newer unpatched version is not deployed.

Generated by OpenCVE AI on August 22, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kk Star Ratings plugin to the latest version that removes the payload vulnerability
  • If an upgrade is not immediately possible, disable or delete the kk Star Ratings plugin to eliminate the attack surface
  • Maintain all other WordPress components and plugins at their latest secure releases and monitor the site for suspicious activity

Generated by OpenCVE AI on August 22, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Title kk Star Ratings <= 5.4.10.3 - Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-22T11:30:39.524Z

Reserved: 2026-03-02T04:06:09.192Z

Link: CVE-2026-3424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T12:16:24.677

Modified: 2026-08-22T12:16:24.677

Link: CVE-2026-3424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T12:30:16Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')