high · CVSS v3 7.2 · EPSS 0.00272
CVE-2026-93430
The GD Rating System WordPress plugin (v3.7.1 and earlier) contains a stored XSS flaw in its AJAX handler that allows unauthenticated users
Overview
The GD Rating System WordPress plugin (v3.7.1 and earlier) contains a stored XSS flaw in its AJAX handler that allows unauthenticated users to inject malicious scripts via the title and URL fields. This flaw can lead to arbitrary script execution on any page that renders the injected content, potentially compromising user sessions and data. The vulnerability is triggered by a publicly exposed nonce, making it easy to exploit without authentication.
Description
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although the AJAX action requires a per-item nonce, that nonce is publicly emitted in the page's
Impact
Confidentiality: attackers can steal session cookies or other sensitive data via injected scripts. Integrity: malicious scripts can modify page content or redirect users. Availability: repeated XSS can degrade user experience. Defenders include site administrators, developers, and security teams.
Remediation
1. Update the GD Rating System plugin to the latest version (≥3.7.2) which removes the vulnerable AJAX endpoint. 2. If an update is not possible, disable or remove the gdrts_live_handler AJAX action or block it via .htaccess or firewall rules. 3. Ensure all user-supplied title and URL inputs are properly sanitized and escaped before rendering. 4. Implement a Content Security Policy that restricts inline scripts and disallows execution of untrusted code. 5. Monitor logs for unusual AJAX requests and XSS attempts.
Risk context
Severity is high (CVSS 7.2) but the EPSS score of 0.00272 indicates a very low probability of exploitation at present. Nonetheless, the flaw is publicly documented and could be leveraged by automated scanners, so timely patching is recommended.
Affected products
- WordPress GD Rating System 3.7.1
- WordPress GD Rating System 3.7.0
- WordPress GD Rating System 3.6.5
- WordPress GD Rating System 3.6.4
- WordPress GD Rating System 3.6.3
- WordPress GD Rating System 3.6.2
- WordPress GD Rating System 3.6.1
- WordPress GD Rating System 3.6.0
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00272