Impact
A missing authorization check (CWE-862) in the Ryviu – Product Reviews for WooCommerce plugin permits users without proper privileges to manipulate review data. The flaw allows creation, modification, or deletion of customer reviews through the plugin’s interface, potentially corrupting the site’s feedback system. No capability for code execution or privilege escalation is listed, so the primary impact is limited to the integrity of review content and the trust customers place in the site’s feedback mechanism.
Affected Systems
The Ryviu – Product Reviews for WooCommerce WordPress plugin, versions from the earliest release through 3.1.26, is affected. Sites running any of these versions are vulnerable if visitors or low‑privilege users can access the review submission or editing features.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. The EPSS score is below 1%, suggesting a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is through the standard review submission or editing interface of the plugin, potentially without authenticated access. The impact remains confined to the integrity of review data, with no disclosed path to more severe compromise.
OpenCVE Enrichment