Impact
The vulnerability is a missing authorization flaw in the BBR Plugins Better Business Reviews WordPress plugin, allowing users to bypass configured access controls. As a result, an attacker could gain unauthorized visibility or manipulation of protected data or functionality. This falls under CWE‑862, indicating a complete lack of checks for proper permissions before executing sensitive actions. The impact is limited to the scope of the plugin, but if the plugin handles sensitive business reviews or customer data, the exposure could be significant.
Affected Systems
WordPress sites running BBR Plugins: Better Business Reviews plugin of version 0.1.1 or earlier are affected. The plugin affects the WordPress installation on which it is installed, and any users that can interact with the plugin’s interfaces are potentially at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Although the exact attack vector is not explicitly stated, it can be inferred that an authenticated user with insufficient privileges—or an attacker exploiting a misconfiguration—could leverage this flaw to access or modify data beyond intended permissions.
OpenCVE Enrichment