Impact
The vulnerability allows an attacker who does not need to authenticate to reference protected resources by manipulating object identifiers. This insecure direct object reference (IDOR) flaw is categorized as CWE‑639 and can lead to unauthorized disclosure of data associated with those objects, potentially exposing confidential user information or configuration data. The impact is limited to reading or possibly modifying objects that should be restricted, but does not provide privilege escalation at a system level.
Affected Systems
The weakness affects the RadiusTheme Review Schema WordPress plugin in all releases up to and including version 3.1.0. Users should verify that their installation is running 3.1.0 or earlier and plan to update to at least 3.1.1, which contains the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting moderate exposure risk. Attackers can exploit this vulnerability without authentication by crafting requests with valid identifiers or by guessing ID values, exploiting the lack of proper authorization checks. The risk is moderate due to the potential for data exposure but does not allow full system compromise.
OpenCVE Enrichment