Description
Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing starfish-reviews allows Privilege Escalation.This issue affects Starfish Review Generation & Marketing: from n/a through <= 3.1.19.
Published: 2025-04-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Starfish Review Generation & Marketing plugin for WordPress contains a missing authorization flaw that enables an attacker to elevate privileges on the site. The vulnerability, identified as CWE-862, means that certain plugin functions are reachable without enforcing proper access controls, allowing an authenticated user with limited rights to obtain higher privileges or perform unauthorized actions via the plugin. The description explicitly states that the flaw permits privilege escalation, but does not detail specific actions or outcomes beyond this capability.

Affected Systems

All versions of the Starfish Review Generation & Marketing plugin from the earliest available release through 3.1.19 are affected. Any WordPress installation that has this plugin installed within that version range is vulnerable. No other WordPress components are mentioned as affected.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as high severity. The EPSS score of less than 1% indicates that, to date, widespread exploitation has not been observed. The vulnerability is not listed in the CISA KEV catalog. While the CVE does not specify how the flaw is triggered, it is reasonable to infer that the attack path involves accessing privileged plugin endpoints that should be gated by authorization checks; an attacker would typically need at least some existing authenticated access to the WordPress administrative area to exploit the missing checks. Thus the risk is that attackers who already have limited site access can promote themselves to higher privileges, which could facilitate further damage such as site takeover or unsafe content manipulation.

Generated by OpenCVE AI on May 1, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Starfish Review Generation & Marketing plugin to version 3.1.20 or later to eliminate the missing authorization flaw.
  • If upgrading is not possible, remove or deactivate the plugin to remove the privilege‑escalation path.
  • Ensure that only administrator‑level users have permission to access the plugin’s configuration or management pages; review role‑based permissions for all WordPress users and enforce strong authentication for administrative accounts.

Generated by OpenCVE AI on May 1, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11741 Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing allows Privilege Escalation. This issue affects Starfish Review Generation & Marketing: from n/a through 3.1.14.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing allows Privilege Escalation. This issue affects Starfish Review Generation & Marketing: from n/a through 3.1.14. Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing starfish-reviews allows Privilege Escalation.This issue affects Starfish Review Generation & Marketing: from n/a through <= 3.1.19.
Title WordPress Starfish Review Generation & Marketing plugin <= 3.1.14 - Arbitrary Option Update to Privilege Escalation vulnerability WordPress Starfish Review Generation & Marketing plugin <= 3.1.19 - Privilege Escalation vulnerability
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing allows Privilege Escalation. This issue affects Starfish Review Generation & Marketing: from n/a through 3.1.14.
Title WordPress Starfish Review Generation & Marketing plugin <= 3.1.14 - Arbitrary Option Update to Privilege Escalation vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:34.270Z

Reserved: 2025-04-16T06:24:40.074Z

Link: CVE-2025-39533

cve-icon Vulnrichment

Updated: 2025-04-17T17:41:39.763Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:56.893

Modified: 2026-04-23T15:29:44.577

Link: CVE-2025-39533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:00:12Z

Weaknesses