CVE-2026-3424
🔶 mediumSummary
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
CVSS Score
5.3
Medium
EPSS Score
0.5
Exploit Probability
Published Date
2026-08-22
First Seen: 2026-08-23
📊 Relative Risk Intelligence
This CVE is Lower Risk - more severe than 19.2% of all 348,756 vulnerabilities in our database.
#281,775
Below average severity
Severity Percentile
Last Modified
2026-08-22
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE IDs (Weakness Types)