Impact
The WordPress Photo Reviews for WooCommerce plugin contains an unauthenticated Insecure Direct Object Reference vulnerability. An attacker who can guess or enumerate review identifiers can read or modify review content, ratings or comments, potentially exposing private customer feedback or manipulating product reviews. This flaw maps to CWE‑639 and enables unauthorized access without authentication, degrading both confidentiality and integrity of review information.
Affected Systems
The vulnerability affects the VillaTheme Photo Reviews for WooCommerce plugin in all versions 1.2.30 and earlier. Tenants running these plugin versions are at risk until an upgrade is applied.
Risk and Exploitability
The CVSS score of 7.5 highlights a high severity risk. Because the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, the public exploitation likelihood is not quantified, but the unauthenticated nature means any internet‑accessible site could be targeted. Attackers can exploit the flaw by issuing unauthenticated HTTP requests to review URLs using guessed identifiers; no special privileges or additional conditions are required.
OpenCVE Enrichment