What the vulnerability does
01Description
Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 4.97.
Explanation of Vulnerability in Simple Terms
02Summary
The Social Proof Testimonials and Reviews plugin for Repuso versions 4.97 and earlier lacks proper authorization checks. A logged-in user with low privileges can trigger a denial-of-service condition by making repeated requests to the plugin. The vulnerability does not affect data confidentiality or integrity, only availability.
What an attacker can do
03Attacker Capabilities
A low-privilege logged-in user can make requests that degrade site performance or cause temporary unavailability.
Potential impact on your site
04Site Impact
Authenticated users can disrupt site availability; you should restrict plugin access to trusted roles and update when a patch is available.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site and network access to send requests.
Key dates
06Disclosure timeline
January 2, 2025
CVE published
April 29, 2026
Record updated