Vulnerabilities > Blazzdev

DATE CVE VULNERABILITY TITLE RISK
2023-12-21 CVE-2023-49765 Authorization Bypass Through User-Controlled Key vulnerability in Blazzdev Rate MY Post
Authorization Bypass Through User-Controlled Key vulnerability in Blaz K.
network
low complexity
blazzdev CWE-639
6.5
2023-01-23 CVE-2022-4673 Unspecified vulnerability in Blazzdev Rate MY Post
The Rate my Post WordPress plugin before 3.3.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
network
low complexity
blazzdev
5.4
2022-09-23 CVE-2022-40310 Race Condition vulnerability in Blazzdev Rate MY Post - WP Rating System
Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes.
network
high complexity
blazzdev CWE-362
3.1
2022-09-23 CVE-2022-40671 Cross-Site Request Forgery (CSRF) vulnerability in Blazzdev Rate MY Post - WP Rating System
Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress.
network
low complexity
blazzdev CWE-352
4.3