Impact
Missing authorization in the Trust.Reviews fb-reviews-widget plugin allows attackers to exploit incorrectly configured access control levels, resulting in unauthorized access to privileged plugin features. The vulnerability aligns with CWE-862 and may enable attackers to modify settings or retrieve sensitive information through the plugin interface.
Affected Systems
The Trust.Reviews plugin for WordPress, supplied by richplugins, is affected. Versions from the earliest releases through version 2.3 inclusive are vulnerable. Users running any of these versions should assess their installation.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can likely exploit the flaw via the WordPress web interface, targeting users who have authenticated but lack sufficient privileges to use the plugin’s restricted functions. Given the low EPSS, widespread exploitation is currently unlikely, but the weakness remains a potential vector for unauthorized configuration changes.
OpenCVE Enrichment
EUVD