Impact
The vulnerability arises from a missing authorization check in the Wisernotify team WiserReview Product Reviews for WooCommerce plugin. The flaw allows an attacker to exploit incorrectly configured access control security levels, potentially viewing or altering product review data without permission. The impact is confined to the review subsystem but could undermine the integrity and trust of user-generated content.
Affected Systems
WordPress sites running the WiserReview Product Reviews for WooCommerce plugin version 2.9 or earlier are affected. No specific sub‑versions are enumerated, so any installation of the plugin up to and including 2.9 is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, requiring an attacker to authenticate or bypass the review management interface, as the description indicates a broken access control flaw. The exploit would grant unauthorized access to review content but does not appear to allow remote code execution or system compromise beyond the plugin’s scope.
OpenCVE Enrichment