Impact
The Customer Reviews for WooCommerce plugin before version 5.116.0 fails to validate nonces or verify user capabilities on several AJAX handlers that manage plugin settings. This omission allows any authenticated user with as low as Subscriber privileges to call administrative handlers, alter plugin options, and reveal store configuration details. The flaw represents an authorization bypass, permitting unauthorized configuration changes and potential information disclosure.
Affected Systems
This issue affects installations of the Customer Reviews for WooCommerce WordPress plugin with a version number earlier than 5.116.0. All affected sites running the plugin before the stated version are potentially vulnerable, regardless of other security controls, because the check is performed purely at the action level within the plugin.
Risk and Exploitability
The vulnerability is exploitable through the normal WordPress AJAX interface, making it reachable from any web page where the user is logged in. While no CVSS score is supplied in the advisory, the impact is significant: a low‑privilege user can modify plugin behavior and leak configuration, which could influence site presentation or compromise other integrations. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment