Impact
The GD Rating System plugin for WordPress contains a stored cross‑site scripting flaw that arises when user supplied values in the 'title' and 'url' rendering arguments are not properly sanitized or escaped in the gdrts_live_handler AJAX handler. An attacker can inject JavaScript that will be stored and served on the site, resulting in the execution of arbitrary code in the browsers of visitors who view the affected pages. This vulnerability allows attackers to deface pages, steal user credentials, or perform session hijacking, thereby compromising both confidentiality and integrity for all site users.
Affected Systems
WordPress installations running the GD Rating System plugin by gdragon, version 3.7.1 or earlier, are affected. The flaw is present in the gdrts_live_handler AJAX action accessed on rating item pages.
Risk and Exploitability
The CVSS score of 7.2 classifies this issue as a high‑severity exploitation risk. The EPSS score is not available, but because the necessary nonce is publicly emitted in the page’s JavaScript block, unauthenticated users can obtain it, eliminating any remote authentication barrier. The vulnerability is not listed in CISA’s KEV catalog, yet its high impact and lack of authentication make it a serious threat for sites that rely on this plugin for rating functionality.
OpenCVE Enrichment