Software: Rating-Widget: Star Review System
Advisory report: https://advisories.dxw.com/advisories/rating-widget-debug-mode/
CVE: Awaiting assignment
CVSS: 5 (Medium; AV:N/AC:L/Au:N/C:P/I:N/A:N)
Rating-Widget: Star Review System allows anybody to turn on debug mode and view
errors and warnings
The plugin allows anybody to turn on debug mode and view errors and warnings.
Errors and warnings should be turned off on production sites as they reveal
information useful to attackers such as paths, and may give hints as to how
themes and plugins are written.
Proof of concept
Add 1/0; to functions.php in the theme
Enable this plugin
(You may need to view source, depending on the theme)
You will see a PHP warning, including the path to your functions.php file
Upgrade to version 2.9.0 or later.
dxw believes in responsible disclosure. Your attention is drawn to our
disclosure policy: https://security.dxw.com/disclosure/
Please contact us on secur...@dxw.com to acknowledge this report if you
received it via a third party (for example, plug...@wordpress.org) as they
generally cannot communicate with us on your behalf.
This vulnerability will be published if we do not receive a response to this
report with 14 days.
2017-11-02: Reported to vendor via email
2017-11-03: Vendor reports it will be fixed in the next release
2017-12-12: Vendor reports issue fixed
Discovered by dxw:
Please visit security.dxw.com for more information.
Sent through the Full Disclosure mailing list
Web Archives & RSS: http://seclists.org/fulldisclosure/