CVE-2024-34763 MEDIUM

CVE-2024-34763: WordPress Builder for WooCommerce reviews shortcodes – ReviewShort plugin <= 1.01.5 - Broken Access Control vulnerability

Vendor Saleswonder Team: Tobias
Product Builder for WooCommerce reviews shortcodes – ReviewShort
Weakness CWE-862 · Missing authorization
Published June 11, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through <= 1.01.5.

Explanation of Vulnerability in Simple Terms

02Summary

ReviewShort, a WooCommerce review shortcode builder plugin, lacks proper authorization checks on certain functions. An unauthenticated attacker can modify review data without permission. The vulnerability affects all versions up to 1.01.5. Site owners should update to a version newer than 1.01.5 when available.

What an attacker can do

03Attacker Capabilities

Modify WooCommerce review data without authentication or authorization.

Potential impact on your site

04Site Impact

Review content on your site can be altered or corrupted by unauthorized parties.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 11, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE