Description
Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews embedder-for-google-reviews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Embedder for Google Reviews: from n/a through <= 1.7.3.
Published: 2025-08-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in PARETO Digital Embedder for Google Reviews allows users to invoke plugin functions that should be restricted by access control lists. The flaw is classified as CWE‑862 and can enable unauthorized viewing or manipulation of Google Reviews data embedded in a WordPress site. The description explicitly states that functionality not properly constrained by ACLs is accessible, thereby compromising confidentiality and integrity of review content.

Affected Systems

All installations of the PARETO Digital Embedder for Google Reviews plugin up to and including version 1.7.3 are affected. The vendor’s advisory lists the affected range as from n/a through <= 1.7.3, indicating that any version prior to or equal to 1.7.3 is vulnerable. WordPress sites that have installed the plugin are therefore at risk.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity; the EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. Likely, an attacker must be authenticated to a WordPress account and simply exploit the missing ACL checks to access restricted plugin functionality. Because the vulnerability does not require elevated privileges beyond those granted to legitimate users, any user with a login could leverage it, yet the overall likelihood of exploitation remains low according to the EPSS metric.

Generated by OpenCVE AI on April 30, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to the latest version (1.7.4 or later) which removes the missing authorization check.
  • If an immediate upgrade is not feasible, temporarily disable or remove the Embedder for Google Reviews plugin until the fix is applied.
  • Apply role-based access controls at the application level so that only users with Administrator or Editor roles can access the plugin’s configuration and processing endpoints, ensuring that function calls are bounded by appropriate capabilities.

Generated by OpenCVE AI on April 30, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24913 Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Embedder for Google Reviews: from n/a through 1.7.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Embedder for Google Reviews: from n/a through 1.7.3. Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews embedder-for-google-reviews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Embedder for Google Reviews: from n/a through <= 1.7.3.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Pareto Digital
Pareto Digital embedder For Google Reviews
Wordpress
Wordpress wordpress
Vendors & Products Pareto Digital
Pareto Digital embedder For Google Reviews
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Embedder for Google Reviews: from n/a through 1.7.3.
Title WordPress Embedder for Google Reviews Plugin <= 1.7.3 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Pareto Digital Embedder For Google Reviews
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:31:02.869Z

Reserved: 2025-07-28T10:56:33.521Z

Link: CVE-2025-54730

cve-icon Vulnrichment

Updated: 2025-08-14T19:33:12.946Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T19:15:38.650

Modified: 2026-04-23T15:32:54.090

Link: CVE-2025-54730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T03:30:27Z

Weaknesses