What the vulnerability does
01Description
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.
Explanation of Vulnerability in Simple Terms
The Plugin for Google Reviews contains an authorization flaw that allows authenticated users with low privileges to modify plugin settings. An attacker with a basic WordPress account can change configuration without proper permission checks. The vulnerability affects version 2.2.2 and requires a valid user login to exploit.
What an attacker can do
Modify plugin settings and configuration without proper authorization.
Potential impact on your site
Unauthorized users can alter Google Reviews plugin behavior, potentially disrupting reviews display or redirecting review traffic.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities