Executive brief
The Reviewer plugin for WordPress, which allows users to insert reviews and comparison tables into posts, contains a security flaw in its access control mechanisms. This vulnerability allows users with low-level 'Subscriber' accounts to perform actions that should be restricted to administrators or editors. While the impact is considered low, it could allow unauthorized users to modify settings or disrupt site operations.
Technical details
A broken access control vulnerability (CWE-862: Missing Authorization) exists in the MVP Themes Reviewer plugin for WordPress in versions up to and including 3.14.2. The flaw stems from a lack of proper authorization checks or nonce validation in certain plugin functions. An authenticated attacker with Subscriber-level permissions can exploit this over the network to perform actions they are not authorized for, potentially impacting the integrity and availability of the plugin's features. As of the advisory date, no official patch has been released.
Affected products
- MVP Themes Reviewer <= 3.14.2
Timeline
- 2026-01-22: disclosed: Reported by Phat RiO
- 2026-07-22: advisory: Patchstack published advisory
- 2026-07-23: advisory: NVD published CVE record