Executive brief
The GD Rating System plugin for WordPress, which allows site owners to add rating and review functionality to their content, is vulnerable to a blind SQL injection attack. An attacker with basic contributor-level access can interact directly with the website's database to extract sensitive information. This could lead to the exposure of user data or internal site configurations, potentially compromising the entire web platform.
Technical details
A Blind SQL Injection vulnerability exists in the Milan Petrovic GD Rating System plugin for WordPress (versions up to and including 3.7). The flaw stems from improper neutralization of special elements used in SQL commands within the gd-rating-system component. An authenticated attacker with 'Contributor' level permissions can exploit this over the network to execute arbitrary SQL queries against the backend database. This allows for the unauthorized extraction of sensitive data, though it does not inherently allow for data modification. As of the advisory date, no official patch has been released.
Affected products
- Milan Petrovic GD Rating System <= 3.7
Timeline
- 2026-05-14: disclosed: Reported by VanTastic
- 2026-07-02: advisory: Initial advisory published by Patchstack
- 2026-07-13: advisory: CVE published to NVD dataset