Executive brief
A vulnerability in the Reviews and Rating – Docplanner plugin for WordPress allows low-level users to perform unauthorized actions. An attacker with a basic account could force the website to scrape external data or send emails from the administrator's address. This could lead to unauthorized database changes and potential reputational damage through spoofed communications.
Technical details
The Reviews and Rating – Docplanner plugin for WordPress (up to version 1.1.4) fails to implement proper authorization checks on several functions. This missing authorization (CWE-862) allows authenticated attackers with subscriber-level permissions or higher to trigger outbound web scraping of external sites. The scraped data can then be written into the 'wp_dp_reviews' database table. Additionally, the vulnerability allows attackers to send feature-request emails that appear to originate from the site administrator's email address. The issue is reachable via network requests by any logged-in user.
Affected products
- berfect Reviews and Rating – Docplanner up to, and including, 1.1.4
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
References
- https://plugins.trac.wordpress.org/browser/reviews-and-rating-docplanner/tags/1.1.4/classes/class-reviews-and-rating-docplanner.php
- https://plugins.trac.wordpress.org/browser/reviews-and-rating-docplanner/tags/1.1.4/classes/class-reviews-and-rating-docplanner.php
- https://plugins.trac.wordpress.org/browser/reviews-and-rating-docplanner/tags/1.1.4/classes/class-reviews-and-rating-docplanner.php
- https://plugins.trac.wordpress.org/browser/reviews-and-rating-docplanner/tags/1.1.4/classes/class-reviews-and-rating-docplanner.php
- https://plugins.trac.wordpress.org/browser/reviews-and-rating-docplanner/tags/1.1.4/classes/class-reviews-and-rating-docplanner.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5f71c834-15ee-48ea-8f8d-6ea4b72a14d8?source=cve