Description
Missing Authorization vulnerability in richplugins Trust.Reviews fb-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trust.Reviews: from n/a through <= 2.3.
Published: 2025-03-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the Trust.Reviews fb-reviews-widget plugin allows attackers to exploit incorrectly configured access control levels, resulting in unauthorized access to privileged plugin features. The vulnerability aligns with CWE-862 and may enable attackers to modify settings or retrieve sensitive information through the plugin interface.

Affected Systems

The Trust.Reviews plugin for WordPress, supplied by richplugins, is affected. Versions from the earliest releases through version 2.3 inclusive are vulnerable. Users running any of these versions should assess their installation.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can likely exploit the flaw via the WordPress web interface, targeting users who have authenticated but lack sufficient privileges to use the plugin’s restricted functions. Given the low EPSS, widespread exploitation is currently unlikely, but the weakness remains a potential vector for unauthorized configuration changes.

Generated by OpenCVE AI on May 1, 2026 at 03:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Trust.Reviews plugin to version 2.4 or later once it is released by the vendor.
  • If an upgrade is not yet available, deactivate or uninstall the fb-reviews-widget component to eliminate the attack surface.
  • Configure WordPress and the Trust.Reviews plugin to restrict access to the plugin’s administrative functions to users with administrator privileges only.

Generated by OpenCVE AI on May 1, 2026 at 03:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8314 Missing Authorization vulnerability in richplugins Trust.Reviews allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Trust.Reviews: from n/a through 2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in richplugins Trust.Reviews allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Trust.Reviews: from n/a through 2.3. Missing Authorization vulnerability in richplugins Trust.Reviews fb-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trust.Reviews: from n/a through <= 2.3.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Thu, 27 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in richplugins Trust.Reviews allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Trust.Reviews: from n/a through 2.3.
Title WordPress Trust.Reviews plugin <= 2.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:59.640Z

Reserved: 2025-03-26T09:21:23.220Z

Link: CVE-2025-30883

cve-icon Vulnrichment

Updated: 2025-03-27T13:10:02.971Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:49.220

Modified: 2026-04-23T15:27:15.517

Link: CVE-2025-30883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:00:06Z

Weaknesses