Description
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
Published: 2026-07-23
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a broken access control flaw that allows subscribers or users with limited privileges to perform actions normally restricted to administrators or higher‑tier roles within the Reviewer plugin. The flaw could enable an attacker to read, modify, or delete review content, potentially compromising site integrity and user data. The weakness is classified as CWE‑862 and carries a CVSS score of 5.4, indicating moderate severity.

Affected Systems

The flaw affects the Reviewer plugin developed by MVP Themes. Any installation of Reviewer with a version number 3.14.2 or earlier is impacted. No further sub‑version detail is provided beyond the upper bound of 3.14.2.

Risk and Exploitability

The EPSS score is reported as less than 1%, suggesting a low likelihood of exploitation at the time of this analysis. The vulnerability is not cataloged in the CISA KEV database. Based on the description, the most probable attack vector involves an authenticated subscriber who can access the plugin’s interface or endpoints; the attacker can then perform unauthorized actions by manipulating request parameters. No specific mitigation from the vendor is noted, so the primary risk is the potential for data tampering or unauthorized content exposure if the plugin remains unpatched.

Generated by OpenCVE AI on August 3, 2026 at 22:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Reviewer to the latest available version (3.14.3 or newer).
  • Limit plugin access only to administrator roles by reviewing the plugin’s role‑based settings.
  • Disable or uninstall the Reviewer plugin if it is not required for site functionality.

Generated by OpenCVE AI on August 3, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mvp Themes
Mvp Themes reviewer
Wordpress
Wordpress wordpress
Vendors & Products Mvp Themes
Mvp Themes reviewer
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
Title WordPress Reviewer plugin <= 3.14.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Mvp Themes Reviewer
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:04:51.859Z

Reserved: 2026-07-22T08:53:30.834Z

Link: CVE-2026-65479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:40.830

Modified: 2026-07-23T16:17:50.900

Link: CVE-2026-65479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses