Junglewise Threat Intelligence

CVE-2026-42639: GD Rating System unauthenticated SQL injection

CVE-2026-42639 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Executive brief

GD Rating System is a WordPress plugin used to manage and display ratings for posts and pages. A critical security flaw allows unauthenticated attackers to interact directly with the website's database. This could lead to the theft of sensitive customer data, administrative credentials, or the complete compromise of the website's information.

Technical details

An unauthenticated SQL injection vulnerability exists in the GD Rating System plugin for WordPress (versions <= 3.6.2). The flaw stems from improper neutralization of special elements used in SQL commands (CWE-89), allowing a remote attacker to send crafted requests to the application without authentication. Successful exploitation enables the attacker to read sensitive data from the database, modify records, or potentially gain administrative access to the WordPress site. The vulnerability is addressed in version 3.7.

Affected products

  • GD Rating System GD Rating System <= 3.6.2

Timeline

  • 2026-01-09: other: Reported by Doan Dinh Van
  • 2026-04-29: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References