Impact
The vulnerability is a CWE-200 Information Exposure and CWE-284 Improper Access Control. An unauthenticated WordPress plugin route allows anyone to query a REST API endpoint that returns individual customer review records, including those pending moderation. The data includes email addresses and other review content that are not intended for public consumption. An attacker can harvest this sensitive information, compromising user privacy and potentially enabling further targeting.
Affected Systems
WordPress sites using YayReviews plugin versions 1.0.4 through 1.4.0 are affected. The vulnerability exists in all builds prior to 1.4.1.
Risk and Exploitability
There is no EPSS score or KEV listing, but the exposure is immediate and does not require elevated privileges; any internet‑connected WordPress installation running the affected plugin can be queried by anyone. While the CVSS score is not provided, the lack of authentication protects the data from an otherwise healthy site, making the risk substantial for all users who receive or post reviews."
OpenCVE Enrichment