PT-2026-104508 · WordPress · Gd Rating System

·

CVE-2026-93430

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GD Rating System versions prior to 3.7.2
Description Insufficient input sanitization and output escaping in the gdrts live handler AJAX function allow unauthenticated attackers to perform Stored Cross-Site Scripting. By manipulating the title and url render arguments, an attacker can inject arbitrary web scripts into pages. These scripts execute when a user accesses the affected page. Although the AJAX action requires a per-item nonce (a unique token used to prevent replay attacks), this token is publicly exposed in the JSON block of the page, allowing any visitor to obtain it.
Recommendations Update GD Rating System to version 3.7.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93430

Affected Products

Gd Rating System