CVE-2014-2839

GD Star Rating 19.22 - Authenticated SQL Injection via s Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/92156
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Mar/399

Scores

EPSS 0.0164
EPSS Percentile 73.9%

Details

CWE
CWE-89
Status published
Products (1)
dev4press/gd_star_rating 19.22
Published Jan 12, 2015
Tracked Since Feb 18, 2026