Impact
The WordPress BizReview plugin up to version 1.5.13 contains a missing authorization flaw that allows attackers to bypass the plugin’s intended access restrictions, potentially exposing or altering review data. This oversight is classified as Broken Access Control (CWE‑862) and carries a CVSS score of 5.3, indicating moderate severity.
Affected Systems
Any WordPress site that has installed the BizReview plugin from its initial release through version 1.5.13 is vulnerable. Site owners should verify the installed plugin version to assess risk.
Risk and Exploitability
The CVSS score signals moderate impact, while the EPSS score of less than 1% suggests a low but not negligible exploitation probability. The attack likely occurs via internal plugin endpoints that require authentication; improperly configured access control levels can be abused. No publicly available exploits are known for this vulnerability.
OpenCVE Enrichment