CVE-2024-12309: Properfraction Rate My Post – Star Rating Plugin By Feedbackwp

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.4 via the get_post_status() due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to vote on unpublished scheduled posts.

Affected products

  • Properfraction Rate My Post – Star Rating Plugin By Feedbackwp: up to and including 4.2.4

Published 2024-12-13. Last modified 2026-06-17.