Impact
The Reviewer plugin version 3.14.2 and earlier contain a SQL injection flaw that allows unauthenticated users to inject arbitrary SQL via a subscription‑related input; the exact parameter is not specified in the CVE description, and the vulnerable vector is inferred from the phrase "subscriber SQL injection". An attacker who can exploit this vector can read, modify, or delete database content, potentially exposing sensitive user information or altering the function of a WordPress site. The weakness is a classic input validation error categorized as CWE-89.
Affected Systems
Sites running MVPThemes Reviewer plugin on WordPress where the installed version is 3.14.2 or older are affected. No other products or vendors are currently listed as impacted.
Risk and Exploitability
The flaw carries a CVSS score of 8.5, indicating high severity. While the EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, the nature of the attack vector—web‑based exploitation through a publicly accessible plugin endpoint—suggests that it could be widely attempted. Hence the risk to affected installations is substantial, with the potential for data loss or unauthorized modification.
OpenCVE Enrichment