Executive brief
The Site Reviews plugin for WordPress, which allows websites to collect and display customer reviews, contains a security flaw that exposes sensitive information. An individual with a basic 'Subscriber' account can access data that should normally be restricted to site administrators. This exposure could lead to the leakage of private user details or internal system information, potentially aiding further attacks on the website.
Technical details
The Site Reviews plugin for WordPress (versions <= 8.0.11) is vulnerable to an insertion of sensitive information into sent data (CWE-201). The flaw allows authenticated attackers with low-level 'Subscriber' privileges to access sensitive information that is not intended for their role. The vulnerability is exploited via a network request without requiring user interaction. The root cause involves improper data filtering or access control within the plugin's review management or display components. A fix is available in version 8.0.12.
Affected products
- Gemini Labs Site Reviews <= 8.0.11
Timeline
- 2026-06-23: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-06-26: advisory: NVD and Patchstack published the advisory
- 2026-06-26: patched: Version 8.0.12 released to address the vulnerability