What the vulnerability does
01Description
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
Explanation of Vulnerability in Simple Terms
The Customer Reviews for WooCommerce plugin through version 5.3.5 contains an access control weakness that allows authenticated users with low privileges to read sensitive information they should not have access to. The vulnerability requires a valid WordPress account but no special interaction. Site administrators should update the plugin immediately to restrict unauthorized data exposure.
What an attacker can do
Read sensitive data they should not have access to as a low-privilege authenticated user.
Potential impact on your site
Customer data or plugin settings may be exposed to low-privilege users like subscribers or contributors.
Conditions required to exploit
Attacker must have a valid WordPress user account with low-level privileges.
Key dates
External resources
Related vulnerabilities