CVE-2023-27625: WordPress Site Reviews plugin <= 6.5.0 - Broken Access Control vulnerability
Published Dec 9, 2024
·Updated
Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through <= 6.5.0.
Affected Software
2 affected components
Gemini Labs Site Reviews (WordPress plugin)<=6.5.0
Paul Ryley Site Reviews (WordPress plugin)<=6.5.0
Remediation
Information
Update the WordPress Site Reviews plugin to the latest available version (at least 6.6.0).
Event History
Dec 9, 2024
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-27625?
CVE-2023-27625 is classified as a Missing Authorization vulnerability which can lead to serious access control issues.
2
How do I fix CVE-2023-27625?
To fix CVE-2023-27625, ensure that your Site Reviews plugin is updated to a version beyond 6.5.0.
3
What versions of Site Reviews are affected by CVE-2023-27625?
CVE-2023-27625 affects all versions of Site Reviews from n/a through 6.5.0.
4
What is the impact of CVE-2023-27625?
Exploiting CVE-2023-27625 could allow unauthorized users to access restricted areas of the Site Reviews plugin.
5
Who is the vendor responsible for CVE-2023-27625?
The vendor responsible for CVE-2023-27625 is Paul Ryley, associated with the Site Reviews plugin for WordPress.