CVE-2024-11977

HIGH

kk Star Ratings - WordPress <=5.4.10 - RCE

Title source: llm
STIX 2.1

Description

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Note: This vulnerability was only partially patched in version 5.4.10.1, and fully patched in 5.4.10.2

Scores

CVSS v3 7.3
EPSS 0.0064
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (2)
collizo4sky/kk Star Ratings – Rate Post & Collect User Feedbacks < 5.4.10
properfraction/kk Star Ratings – Rate Post & Collect User Feedbacks < 5.4.10
Published Dec 21, 2024
Tracked Since Feb 18, 2026