Impact
The vulnerability is an Authorization Bypass Through User‑Controlled Key flaw, identified as CWE‑639. It permits an attacker who can influence request parameters to circumvent internal access controls and retrieve or modify data that should be protected. The flaw can expose review content, ratings, and possibly configuration settings, enabling unauthorized readers or tamperers.
Affected Systems
This issue affects the Ultimate Reviews plugin for WordPress, released by Rustaurius, on any installation running a version up to and including 3.2.16. Sites with earlier releases are also vulnerable because the plugin’s access checks were never fixed in those versions.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, while an EPSS of less than 1% suggests a low probability of exploitation. The plugin is not listed in the CISA KEV catalog. Exploitation likely requires the attacker to send crafted requests to the plugin’s administrative URLs, which are traditionally protected by WordPress authentication but lack sufficient authorization validation to enforce proper access rights.
OpenCVE Enrichment