What the vulnerability does
01Description
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.
Explanation of Vulnerability in Simple Terms
Customer Reviews for WooCommerce versions up to 5.38.1 lack proper authorization checks, allowing authenticated users to modify review data they should not have access to. An attacker with a low-privilege account can alter or tamper with customer reviews. The vulnerability requires a valid user login but no special interaction. Update to a version newer than 5.38.1 to resolve this issue.
What an attacker can do
Modify or tamper with customer reviews on the site using a low-privilege account.
Potential impact on your site
Customer reviews can be altered or deleted by unauthorized users, damaging trust and review integrity.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities