Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Security & Risk Analysis

wordpress.org/plugins/rate-star-review

Boost engagement with AJAX-driven star ratings, reviews, vote buttons for content.

60 active installs v1.6.4 PHP 7.4+ WP 5.1+ Updated Jan 17, 2025
ajaxratereviewstarvote
66
C · Use Caution
CVEs total3
Unpatched1
Last CVEMay 11, 2026
Safety Verdict

Is Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Safe to Use in 2026?

Use With Caution

Score 66/100

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

3 known CVEs 1 unpatched Last CVE: May 11, 2026Updated 1yr ago
Risk Assessment

The rate-star-review v1.6.4 plugin exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known critical or high severity vulnerabilities currently unpatched, there are significant concerns regarding its attack surface. A substantial portion of its AJAX handlers lack proper authentication checks, presenting a clear risk. The static analysis reveals that 6 out of 12 entry points are unprotected. Furthermore, 3 out of 6 analyzed taint flows have unsanitized paths, which, although not classified as critical or high severity in this analysis, warrants attention as it indicates potential input sanitization weaknesses. The vulnerability history shows 2 medium severity CVEs related to Cross-site Scripting in the past, suggesting that while these have been addressed, the plugin has had issues with input sanitization and output escaping previously. The plugin also has a moderate percentage of improperly escaped outputs (22%). Overall, the plugin has strengths in its database interaction and has addressed past vulnerabilities, but the unprotected AJAX endpoints and the presence of unsanitized taint flows are significant security weaknesses that need immediate attention.

Key Concerns

  • AJAX handlers without authentication checks
  • Taint flows with unsanitized paths
  • Improperly escaped outputs
  • Medium severity vulnerabilities in history
Vulnerabilities
3 published

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2026-4301medium · 4.3Missing Authorization

Rate Star Review Vote <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'rating_id' Parameter

May 11, 2026Unpatched
CVE-2024-13392medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 17, 2025 Patched in 1.6.4 (1d)
CVE-2023-52213medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Rate Star Review <= 1.5.1 - Reflected Cross-Site Scripting

Jan 3, 2024 Patched in 1.5.2 (20d)
Version History

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
78 escaped
Nonce Checks
2
Capability Checks
2
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped100 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

6 flows3 with unsanitized paths
vwrsr_vote (rate-star-review.php:364)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Attack Surface

Entry Points12
Unprotected6

AJAX Handlers 6

authwp_ajax_vwrsr_voterate-star-review.php:70
noprivwp_ajax_vwrsr_voterate-star-review.php:71
authwp_ajax_vwrsr_reviewrate-star-review.php:73
noprivwp_ajax_vwrsr_reviewrate-star-review.php:74
authwp_ajax_vwrsr_reviewsrate-star-review.php:76
noprivwp_ajax_vwrsr_reviewsrate-star-review.php:77

Shortcodes 6

[videowhisper_vote] rate-star-review.php:60
[videowhisper_review] rate-star-review.php:62
[videowhisper_reviews] rate-star-review.php:63
[videowhisper_rating] rate-star-review.php:64
[videowhisper_ratings] rate-star-review.php:65
[videowhisper_review_featured] rate-star-review.php:66
WordPress Hooks 5
filterthe_contentrate-star-review.php:56
actioninitrate-star-review.php:1604
actionplugins_loadedrate-star-review.php:1606
actionadmin_menurate-star-review.php:1607
actionadmin_bar_menurate-star-review.php:1608
Maintenance & Trust

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJan 17, 2025
PHP min version7.4
Downloads12K

Community Trust

Rating100/100
Number of ratings2
Active installs60
Developer Profile

Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Developer Profile

videowhisper

13 plugins · 1K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
1046 days
View full developer profile
Detection Fingerprints

How We Detect Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rate-star-review/scripts/semantic/semantic.min.css/wp-content/plugins/rate-star-review/scripts/semantic/semantic.min.js
Script Paths
https://cdn.jsdelivr.net/npm/fomantic-ui@2.8.7/dist/semantic.min.csshttps://cdn.jsdelivr.net/npm/fomantic-ui@2.8.7/dist/semantic.min.js

HTML / DOM Fingerprints

CSS Classes
uiyellowlargestarratingreadonlycardright+2 more
Data Attributes
data-ratingdata-max-rating
JS Globals
VWrateStarReview
REST Endpoints
/wp-json/vwrsr_vote/wp-json/vwrsr_review/wp-json/vwrsr_reviews
Shortcode Output
[videowhisper_vote][videowhisper_review][videowhisper_reviews][videowhisper_rating]
FAQ

Frequently Asked Questions about Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings