Blazzdev's vulnerability footprint centers on a narrowly scoped WordPress rating plugin (Rate My Post) that serves a niche audience of site administrators. The recurring exposure involves access-control and request-validation weaknesses—including authorization bypass through user-controlled keys, authentication spoofing, race conditions, and cross-site request forgery—that are typical of plugin-layer implementations where privilege escalation and state-management boundaries become attack vectors. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blazzdev over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51667HIGH Authentication Bypass by Spoofing vulnerability in FeedbackWP Rate my Post – WP Rating System allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Rat | Jun 4, 2024 | 8.2 | 22 | NO | NO |
CVE-2022-4673MEDIUM The Rate my Post WordPress plugin before 3.3.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform St | Jan 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-49765MEDIUM Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1 | Dec 21, 2023 | 6.5 | 18 | NO | NO |
CVE-2022-40671MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress. | Sep 23, 2022 | 4.3 | 18 | NO | NO |
CVE-2024-32823MEDIUM Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3. | Apr 24, 2024 | 5.3 | 17 | NO | NO |
Authenticated (subscriber+) Race Condition vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress allows attackers to increase/decrease votes. | Sep 23, 2022 | 3.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blazzdev.
Media articles that mention a CVE ID that affects a product developed by Blazzdev — matched by CVE ID, not by vendor name.