Impact
Missing Authorization vulnerability in the Repuso Social proof testimonials and reviews plugin allows an attacker to perform privileged actions that should be restricted, which can lead to unauthorized viewing, modification, or deletion of testimonial data. The weakness is identified by CWE-862.
Affected Systems
The vulnerability exists in the Repuso Social proof testimonials and reviews plugin for WordPress, affecting all versions from the initial release up to and including version 5.29. Any WordPress site that has this plugin installed and uses a version in that range is potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and an EPSS of less than 1% indicates a low likelihood of exploitation in the wild. The plugin is not listed in CISA’s KEV catalog. The access control flaw can be exploited through the plugin’s web interface; an attacker can send crafted HTTP requests to endpoints that the plugin exposes, thereby bypassing normal authorization checks. With no special privileges required, the attack vector is most likely remote via web traffic.
OpenCVE Enrichment