{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gd-rating-system--3.7.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gd_rating_system_project:gd_rating_system:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-93430"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GD Rating System (\u003c= 3.7.1)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe GD Rating System plugin for WordPress, in all versions up to and including 3.7.1, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. The flaw exists within the gdrts_live_handler AJAX action, which fails to adequately sanitize the 'title' and 'url' parameters before processing. An attacker can leverage this to inject arbitrary malicious web scripts into the application. While the vulnerable AJAX endpoint is intended to be protected by a nonce, the plugin exposes this nonce publicly within a JSON block inside the HTML source of every page rendering a rating component. This exposure renders the nonce ineffective as an authentication or authorization control, allowing unauthenticated attackers to trigger the injection successfully. The vulnerability poses a significant risk as it allows for the execution of scripts in the context of victim users' browsers, potentially leading to session hijacking, defacement, or unauthorized actions performed on behalf of authenticated administrators.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker visits a public page on the WordPress site that utilizes the GD Rating System plugin.\u003c/li\u003e\n\u003cli\u003eAttacker parses the HTML source code of the page to locate the script tag with the class 'gdrts-rating-data'.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the valid nonce required for the AJAX action from the JSON block found within the script tag.\u003c/li\u003e\n\u003cli\u003eAttacker constructs an HTTP POST request targeting the /wp-admin/admin-ajax.php endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the 'action' parameter set to 'gdrts_live_handler' and includes the stolen nonce in the request.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious JavaScript payloads into the 'title' or 'url' parameters of the POST request.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the request and persists the malicious payload into the site database without proper sanitization.\u003c/li\u003e\n\u003cli\u003eThe payload executes in the browser of any user (including administrators) who visits the page where the rating item is displayed.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. This can lead to the theft of session cookies, administrative account takeover, redirecting users to malicious sites, or performing unauthorized actions within the WordPress dashboard if an administrator views the injected content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the GD Rating System plugin to a version beyond 3.7.1 immediately to patch the sanitization logic.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, deactivate the GD Rating System plugin to prevent exploitation of the gdrts_live_handler endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor web application firewall logs for HTTP POST requests to 'admin-ajax.php' containing unusual strings in the 'title' or 'url' fields, specifically those attempting to inject script tags or event handlers.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to access the vulnerable AJAX handler if feasible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T06:54:20Z","date_published":"2026-10-03T06:54:20Z","id":"https://feed.craftedsignal.io/briefs/2026-10-gd-rating-system-xss/","summary":"An unauthenticated Stored Cross-Site Scripting vulnerability in the GD Rating System plugin for WordPress allows attackers to execute arbitrary JavaScript via the gdrts_live_handler AJAX action by bypassing a trivially accessible nonce.","title":"Stored Cross-Site Scripting in GD Rating System WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-gd-rating-system-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - GD Rating System (\u003c= 3.7.1)","version":"https://jsonfeed.org/version/1.1"}