CVE-2023-4642


kk Star Ratings < 5.4.6 - Rating Tampering via Race Condition

The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.



We have discovered 1,593 live websites that are affected by CVE-2023-4642.

Contact us to get more info




Affected Software

Product  kk Star Ratings
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 5.4.6
Total Vulnerable Versions49
Vulnerable Domains1,593 live websites (34.76% of kk Star Ratings install base)


Common Weakness Enumeration


CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-4642 and the relative popularity of websites


Details

  • Published - Nov 27, 2023
  • Updated - Nov 27, 2023

Credits

  • Mohammad Reza Omrani (finder)
  • WPScan (coordinator)





Countries

United States300 websites



Vietnam364 websites
France191 websites
Poland115 websites
Iran103 websites
Germany86 websites
Spain57 websites
Czech Republic45 websites
Netherlands29 websites
Russia23 websites

TLDs

.com609 websites
.pl99 websites
.fr85 websites
.net82 websites
.org67 websites
.de38 websites
.cz37 websites
.es22 websites
.ru21 websites
.com.br20 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-4642 through included software libraries and plugins.



References


Websites affected by CVE-2023-4642

Top websites that are affected by CVE-2023-4642. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.******.at Austria*,***
*********.org Spain**,***
*********.co United States**,***
**************.org United States**,***
***.*******.com United States**,***
**************.com Spain**,***
************.com Vietnam**,***
******.**.id Indonesia**,***
******.net Vietnam**,***
********.***.vn Vietnam**,***
See full domain list