CVE-2014-2839
GD Star Rating 19.22 - Authenticated SQL Injection via s Parameter
Title source: llmDescription
SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
https://advisories.dxw.com/advisories/csrf-and-blind-sql-injection-in-gd-star-rating-1-9-22/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/92156
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Mar/399
Scores
EPSS
0.0164
EPSS Percentile
73.9%
Details
CWE
CWE-89
Status
published
Products (1)
dev4press/gd_star_rating
19.22
Published
Jan 12, 2015
Tracked Since
Feb 18, 2026