What the vulnerability does
01Description
Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through <= 6.10.2.
Explanation of Vulnerability in Simple Terms
02Summary
Site Reviews versions 6.10.2 and earlier lack proper authorization checks, allowing unauthenticated attackers to modify site content. An attacker can send a network request to alter reviews or related data without needing to log in or interact with a user. This affects the integrity of review data on sites using the vulnerable plugin.
What an attacker can do
03Attacker Capabilities
Modify or alter site reviews and related content without authentication.
Potential impact on your site
04Site Impact
Attackers can tamper with reviews, ratings, or review metadata without a user account.
Conditions required to exploit
05Prerequisites
Network access to the site; no login or user interaction required.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 29, 2026
Record updated