The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/79bb5acb-ea56-41a9-83a1-28a181ae41e2 | third party advisory exploit |
https://plugins.trac.wordpress.org/changeset/2618234 | third party advisory patch |