What the vulnerability does
01Description
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
Explanation of Vulnerability in Simple Terms
02Summary
The Customer Reviews for WooCommerce plugin through version 5.46.0 fails to properly check user permissions before allowing access to sensitive review data. A logged-in user with low privileges can read reviews and associated information they should not have access to. The vulnerability requires an active user account but no special interaction from the victim.
What an attacker can do
03Attacker Capabilities
Read reviews and review data that should be restricted to other users or administrators.
Potential impact on your site
04Site Impact
Customer review data may be exposed to unauthorized users, compromising privacy and potentially revealing sensitive information.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the WooCommerce site.
Key dates
06Disclosure timeline
April 16, 2024
CVE published
April 8, 2026
Record updated