Skip to content
Threat Feed
high advisory

Stored Cross-Site Scripting in GD Rating System WordPress Plugin

An unauthenticated Stored Cross-Site Scripting vulnerability in the GD Rating System plugin for WordPress allows attackers to execute arbitrary JavaScript via the gdrts_live_handler AJAX action by bypassing a trivially accessible nonce.

CVE search metadata

CVE search record: CVE-2026-93430. Severity: high. CVSS: 7.2. KEV: no. Product: GD Rating System (<= 3.7.1). Brief: Stored Cross-Site Scripting in GD Rating System WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-gd-rating-system-xss/

The GD Rating System plugin for WordPress, in all versions up to and including 3.7.1, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. The flaw exists within the gdrts_live_handler AJAX action, which fails to adequately sanitize the 'title' and 'url' parameters before processing. An attacker can leverage this to inject arbitrary malicious web scripts into the application. While the vulnerable AJAX endpoint is intended to be protected by a nonce, the plugin exposes this nonce publicly within a JSON block inside the HTML source of every page rendering a rating component. This exposure renders the nonce ineffective as an authentication or authorization control, allowing unauthenticated attackers to trigger the injection successfully. The vulnerability poses a significant risk as it allows for the execution of scripts in the context of victim users' browsers, potentially leading to session hijacking, defacement, or unauthorized actions performed on behalf of authenticated administrators.

Attack Chain

  1. Attacker visits a public page on the WordPress site that utilizes the GD Rating System plugin.
  2. Attacker parses the HTML source code of the page to locate the script tag with the class 'gdrts-rating-data'.
  3. Attacker extracts the valid nonce required for the AJAX action from the JSON block found within the script tag.
  4. Attacker constructs an HTTP POST request targeting the /wp-admin/admin-ajax.php endpoint.
  5. Attacker includes the 'action' parameter set to 'gdrts_live_handler' and includes the stolen nonce in the request.
  6. Attacker injects malicious JavaScript payloads into the 'title' or 'url' parameters of the POST request.
  7. The plugin processes the request and persists the malicious payload into the site database without proper sanitization.
  8. The payload executes in the browser of any user (including administrators) who visits the page where the rating item is displayed.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. This can lead to the theft of session cookies, administrative account takeover, redirecting users to malicious sites, or performing unauthorized actions within the WordPress dashboard if an administrator views the injected content.

Recommendation

Prioritized actions for security teams:

  • Update the GD Rating System plugin to a version beyond 3.7.1 immediately to patch the sanitization logic.
  • If a patch is unavailable, deactivate the GD Rating System plugin to prevent exploitation of the gdrts_live_handler endpoint.
  • Monitor web application firewall logs for HTTP POST requests to 'admin-ajax.php' containing unusual strings in the 'title' or 'url' fields, specifically those attempting to inject script tags or event handlers.
  • Deploy the Sigma rule below to detect attempts to access the vulnerable AJAX handler if feasible.

Immediate actions

Update GD Rating System plugin beyond 3.7.1

IT Operations 48h

Mitigations

Deactivate GD Rating System plugin

immediate IT Operations

CVE-2026-93430

Detection coverage 1

Detects CVE-2026-93430 Exploitation - POST to gdrts_live_handler

high

Detects exploitation attempts against the GD Rating System plugin by monitoring for POST requests to the AJAX handler containing common XSS vectors.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →