CVE-2022-45369 MEDIUM

CVE-2022-45369: WordPress Plugin for Google Reviews plugin <= 2.2.2 - Auth. Broken Access Control vulnerability

Vendor Richplugins
Product Plugin for Google Reviews (WordPress plugin)
Weakness CWE-264
Published November 18, 2022
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Auth. (subscriber+) Broken Access Control vulnerability in Plugin for Google Reviews plugin <= 2.2.2 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The Plugin for Google Reviews contains an authorization flaw that allows authenticated users with low privileges to modify plugin settings. An attacker with a basic WordPress account can change configuration without proper permission checks. The vulnerability affects version 2.2.2 and requires a valid user login to exploit.

What an attacker can do

03Attacker Capabilities

Modify plugin settings and configuration without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can alter Google Reviews plugin behavior, potentially disrupting reviews display or redirecting review traffic.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).

Key dates

06Disclosure timeline

November 18, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE