Impact
This vulnerability is a broken access control flaw that allows subscribers or users with limited privileges to perform actions normally restricted to administrators or higher‑tier roles within the Reviewer plugin. The flaw could enable an attacker to read, modify, or delete review content, potentially compromising site integrity and user data. The weakness is classified as CWE‑862 and carries a CVSS score of 5.4, indicating moderate severity.
Affected Systems
The flaw affects the Reviewer plugin developed by MVP Themes. Any installation of Reviewer with a version number 3.14.2 or earlier is impacted. No further sub‑version detail is provided beyond the upper bound of 3.14.2.
Risk and Exploitability
The EPSS score is reported as less than 1%, suggesting a low likelihood of exploitation at the time of this analysis. The vulnerability is not cataloged in the CISA KEV database. Based on the description, the most probable attack vector involves an authenticated subscriber who can access the plugin’s interface or endpoints; the attacker can then perform unauthorized actions by manipulating request parameters. No specific mitigation from the vendor is noted, so the primary risk is the potential for data tampering or unauthorized content exposure if the plugin remains unpatched.
OpenCVE Enrichment