Executive brief
BizReview is a WordPress plugin used for managing business reviews and directories. A security flaw in the plugin allows unauthorized individuals to bypass access controls due to missing authorization checks. This could allow an attacker to perform actions or modify settings that should be restricted to administrators, potentially impacting the integrity of the review platform.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Foysal Imran BizReview plugin for WordPress through version 1.5.13. The flaw stems from incorrectly configured access control security levels, where the application fails to perform necessary permission checks on certain functions. A remote, unauthenticated attacker can exploit this vulnerability over the network without any user interaction. Successful exploitation allows the attacker to execute actions or modify data that should require higher privilege levels, though the reported impact is limited to integrity (CVSS:I:L). No official patch has been confirmed in the primary advisory text.
Affected products
- Foysal Imran BizReview <= 1.5.13
Timeline
- 2026-01-04: other: Vulnerability reported by researcher Legion Hunter
- 2026-02-03: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD