CPE
An unauthenticated Stored Cross-Site Scripting vulnerability in the GD Rating System plugin for WordPress allows attackers to execute arbitrary JavaScript via the gdrts_live_handler AJAX action by bypassing a trivially accessible nonce.