CVE-2026-3424
Received Received - Intake

Arbitrary Shortcode Execution in kk Star Ratings WordPress Plugin

Vulnerability report for CVE-2026-3424, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-22

Last updated on: 2026-08-22

Assigner: Wordfence

Description

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-22
Last Modified
2026-08-22
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kk_star_ratings rate_post_and_collect_user_feedbacks to 5.4.10.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the kk Star Ratings WordPress plugin up to version 5.4.10.3. It allows unauthenticated attackers to execute arbitrary shortcodes by exploiting improper validation of the 'payload' value before running do_shortcode. This could let attackers perform unintended actions on the site.

Detection Guidance

Check for the presence of the kk Star Ratings plugin in your WordPress installation. Look for versions up to and including 5.4.10.3. Review server logs for suspicious shortcode execution attempts or unauthorized actions.

Impact Analysis

An attacker could exploit this to run malicious shortcodes, potentially defacing your site, stealing data, or redirecting visitors. Since no authentication is required, any visitor could trigger the issue if the plugin is installed.

Compliance Impact

This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes, which could lead to unauthorized data access, modification, or exfiltration. For GDPR, this may violate principles of data protection and user consent. For HIPAA, it could compromise protected health information if exploited in healthcare-related WordPress sites.

Mitigation Strategies
  • Update the kk Star Ratings plugin to the latest version immediately.
  • Disable the plugin if an update is not available or if suspicious activity is detected.
  • Review user roles and permissions to limit access to the plugin's functionality.
  • Monitor for unauthorized shortcode execution or unusual server activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3424. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart