<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:gd_rating_system_project:gd_rating_system:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agd_rating_system_projectgd_rating_systemwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 06:54:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agd_rating_system_projectgd_rating_systemwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in GD Rating System WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-gd-rating-system-xss/</link><pubDate>Sat, 03 Oct 2026 06:54:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gd-rating-system-xss/</guid><description>An unauthenticated Stored Cross-Site Scripting vulnerability in the GD Rating System plugin for WordPress allows attackers to execute arbitrary JavaScript via the gdrts_live_handler AJAX action by bypassing a trivially accessible nonce.</description><content:encoded><![CDATA[<p>The GD Rating System plugin for WordPress, in all versions up to and including 3.7.1, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. The flaw exists within the gdrts_live_handler AJAX action, which fails to adequately sanitize the 'title' and 'url' parameters before processing. An attacker can leverage this to inject arbitrary malicious web scripts into the application. While the vulnerable AJAX endpoint is intended to be protected by a nonce, the plugin exposes this nonce publicly within a JSON block inside the HTML source of every page rendering a rating component. This exposure renders the nonce ineffective as an authentication or authorization control, allowing unauthenticated attackers to trigger the injection successfully. The vulnerability poses a significant risk as it allows for the execution of scripts in the context of victim users' browsers, potentially leading to session hijacking, defacement, or unauthorized actions performed on behalf of authenticated administrators.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker visits a public page on the WordPress site that utilizes the GD Rating System plugin.</li>
<li>Attacker parses the HTML source code of the page to locate the script tag with the class 'gdrts-rating-data'.</li>
<li>Attacker extracts the valid nonce required for the AJAX action from the JSON block found within the script tag.</li>
<li>Attacker constructs an HTTP POST request targeting the /wp-admin/admin-ajax.php endpoint.</li>
<li>Attacker includes the 'action' parameter set to 'gdrts_live_handler' and includes the stolen nonce in the request.</li>
<li>Attacker injects malicious JavaScript payloads into the 'title' or 'url' parameters of the POST request.</li>
<li>The plugin processes the request and persists the malicious payload into the site database without proper sanitization.</li>
<li>The payload executes in the browser of any user (including administrators) who visits the page where the rating item is displayed.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. This can lead to the theft of session cookies, administrative account takeover, redirecting users to malicious sites, or performing unauthorized actions within the WordPress dashboard if an administrator views the injected content.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Update the GD Rating System plugin to a version beyond 3.7.1 immediately to patch the sanitization logic.</li>
<li>If a patch is unavailable, deactivate the GD Rating System plugin to prevent exploitation of the gdrts_live_handler endpoint.</li>
<li>Monitor web application firewall logs for HTTP POST requests to 'admin-ajax.php' containing unusual strings in the 'title' or 'url' fields, specifically those attempting to inject script tags or event handlers.</li>
<li>Deploy the Sigma rule below to detect attempts to access the vulnerable AJAX handler if feasible.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-vulnerability</category><category>wordpress</category></item></channel></rss>