Description
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized access to review data via IDOR
Action: Patch Immediately
AI Analysis

Impact

The WordPress Photo Reviews for WooCommerce plugin contains an unauthenticated Insecure Direct Object Reference vulnerability. An attacker who can guess or enumerate review identifiers can read or modify review content, ratings or comments, potentially exposing private customer feedback or manipulating product reviews. This flaw maps to CWE‑639 and enables unauthorized access without authentication, degrading both confidentiality and integrity of review information.

Affected Systems

The vulnerability affects the VillaTheme Photo Reviews for WooCommerce plugin in all versions 1.2.30 and earlier. Tenants running these plugin versions are at risk until an upgrade is applied.

Risk and Exploitability

The CVSS score of 7.5 highlights a high severity risk. Because the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, the public exploitation likelihood is not quantified, but the unauthenticated nature means any internet‑accessible site could be targeted. Attackers can exploit the flaw by issuing unauthenticated HTTP requests to review URLs using guessed identifiers; no special privileges or additional conditions are required.

Generated by OpenCVE AI on October 1, 2026 at 15:23 UTC.

Remediation

Vendor Solution

Update the WordPress Photo Reviews for WooCommerce plugin to the latest available version (at least 1.2.31).


OpenCVE Recommended Actions

  • Upgrade the WordPress Photo Reviews for WooCommerce plugin to version 1.2.31 or later.
  • Restrict direct URL access to review resources by configuring server rules or the plugin to require authentication for review IDs.
  • Monitor web server logs for repeated attempts to access review IDs that do not belong to the logged‑in user and investigate any suspicious activity.

Generated by OpenCVE AI on October 1, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
Title WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T15:11:19.557Z

Reserved: 2026-09-26T00:17:50.216Z

Link: CVE-2026-100517

cve-icon Vulnrichment

Updated: 2026-10-01T15:10:47.667Z

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:17.810

Modified: 2026-10-01T16:17:28.100

Link: CVE-2026-100517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key