CVE-2024-32684 MEDIUM

CVE-2024-32684: WordPress WP Ultimate Review plugin <= 2.2.5 - Broken Access Control on Review vulnerability

Vendor Wpmet
Product Wp Ultimate Review
Weakness CWE-862 · Missing authorization
Published April 22, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

Explanation of Vulnerability in Simple Terms

02Summary

WP Ultimate Review versions up to 2.2.5 lack proper authorization checks, allowing unauthenticated attackers to modify review data via network requests. The vulnerability does not expose sensitive information or disrupt site availability, but permits unauthorized changes to review content. Site administrators should update to a version newer than 2.2.5.

What an attacker can do

03Attacker Capabilities

Modify or create reviews without logging in.

Potential impact on your site

04Site Impact

Attackers can alter or inject fake reviews, damaging site credibility and user trust.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

April 22, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE