CVE-2026-93430
Received Received - Intake

Stored Cross-Site Scripting in GD Rating System WordPress Plugin

Vulnerability report for CVE-2026-93430, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Although the AJAX action requires a per-item nonce, that nonce is publicly emitted in the page's <script class="gdrts-rating-data"> JSON block on every page rendering the rating item, making it obtainable by any unauthenticated visitor and therefore not an authentication barrier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gd_rating_system gdrts to 3.7.1 (inc)
gd_rating_system gd_rating_system to 3.7.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The GD Rating System plugin for WordPress has a stored cross-site scripting (XSS) vulnerability due to insufficient input sanitization and output escaping in the 'title' and 'url' render arguments of the gdrts_live_handler AJAX function. This allows unauthenticated attackers to inject malicious scripts into pages. The vulnerability exists because a required nonce for the AJAX action is publicly exposed in a page's JSON block, making it accessible to any visitor.

Detection Guidance

Check if the GD Rating System plugin is installed and its version. Look for suspicious scripts in pages where ratings are displayed. Use WordPress admin to inspect plugin versions or check files for 'gdrts_live_handler' references.

Impact Analysis

This vulnerability allows attackers to inject arbitrary web scripts into pages that execute when users access them. This could lead to unauthorized actions on behalf of users, data theft, or defacement of websites using the plugin. Since the plugin is for WordPress, it primarily impacts websites using this plugin.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthenticated attackers to inject malicious scripts into web pages. Such scripts could steal user data or session cookies, leading to unauthorized access to sensitive information. This violates principles of data protection and confidentiality required by these regulations.

Mitigation Strategies

Update the GD Rating System plugin to the latest version if available. If not, consider disabling the plugin temporarily until a patch is released. Review and sanitize user inputs in the plugin's settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93430. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart