Software: Rating-Widget: Star Review System
Version: 2.8.9
Advisory report:
CVE: Awaiting assignment
CVSS: 5 (Medium; AV:N/AC:L/Au:N/C:P/I:N/A:N)

Rating-Widget: Star Review System allows anybody to turn on debug mode and view 
errors and warnings

The plugin allows anybody to turn on debug mode and view errors and warnings. 
Errors and warnings should be turned off on production sites as they reveal 
information useful to attackers such as paths, and may give hints as to how 
themes and plugins are written.

Proof of concept

Add 1/0; to functions.php in the theme
Enable this plugin
Visit http://localhost/?rwdbg=true
(You may need to view source, depending on the theme)
You will see a PHP warning, including the path to your functions.php file

Upgrade to version 2.9.0 or later.

Disclosure policy
dxw believes in responsible disclosure. Your attention is drawn to our 
disclosure policy:

Please contact us on to acknowledge this report if you 
received it via a third party (for example, as they 
generally cannot communicate with us on your behalf.

This vulnerability will be published if we do not receive a response to this 
report with 14 days.


2017-10-30: Discovered
2017-11-02: Reported to vendor via email
2017-11-03: Vendor reports it will be fixed in the next release
2017-12-12: Vendor reports issue fixed

Discovered by dxw:
Tom Adams
Please visit for more information.

Sent through the Full Disclosure mailing list
Web Archives & RSS:

Reply via email to