Description
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although the AJAX action requires a per-item nonce, that nonce is publicly emitted in the page's <script class="gdrts-rating-data"> JSON block on every page rendering the rating item, making it obtainable by any unauthenticated visitor and therefore not an authentication barrier.
Published: 2026-10-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The GD Rating System plugin for WordPress contains a stored cross‑site scripting flaw that arises when user supplied values in the 'title' and 'url' rendering arguments are not properly sanitized or escaped in the gdrts_live_handler AJAX handler. An attacker can inject JavaScript that will be stored and served on the site, resulting in the execution of arbitrary code in the browsers of visitors who view the affected pages. This vulnerability allows attackers to deface pages, steal user credentials, or perform session hijacking, thereby compromising both confidentiality and integrity for all site users.

Affected Systems

WordPress installations running the GD Rating System plugin by gdragon, version 3.7.1 or earlier, are affected. The flaw is present in the gdrts_live_handler AJAX action accessed on rating item pages.

Risk and Exploitability

The CVSS score of 7.2 classifies this issue as a high‑severity exploitation risk. The EPSS score is not available, but because the necessary nonce is publicly emitted in the page’s JavaScript block, unauthenticated users can obtain it, eliminating any remote authentication barrier. The vulnerability is not listed in CISA’s KEV catalog, yet its high impact and lack of authentication make it a serious threat for sites that rely on this plugin for rating functionality.

Generated by OpenCVE AI on October 3, 2026 at 06:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest GD Rating System plugin release (any version newer than 3.7.1).
  • If an immediate update is not possible, disable the GD Rating System plugin until a patched version is deployed.
  • As a temporary precaution, restrict public access to pages that render rating items or remove those items from the site until the vulnerability is fixed.

Generated by OpenCVE AI on October 3, 2026 at 06:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although the AJAX action requires a per-item nonce, that nonce is publicly emitted in the page's &lt;script class="gdrts-rating-data"&gt; JSON block on every page rendering the rating item, making it obtainable by any unauthenticated visitor and therefore not an authentication barrier.
Title GD Rating System <= 3.7.1 - Unauthenticated Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:45.202Z

Reserved: 2026-09-17T21:04:02.914Z

Link: CVE-2026-93430

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:25.920Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:46.727

Modified: 2026-10-03T16:16:44.147

Link: CVE-2026-93430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')