First published: Thu Jan 02 2025(Updated: )
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through 5.36.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Customer Reviews | <5.36.1 | |
WP Customer Reviews | <=5.36.0 | |
WP Customer Reviews | <=5.36.0 |
Update the WordPress Customer Reviews for WooCommerce plugin to the latest available version (at least 5.36.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45101 is classified as a missing authorization vulnerability which poses a significant risk due to incorrectly configured access control levels.
To fix CVE-2023-45101, update the CusRev Customer Reviews for WooCommerce plugin to version 5.36.1 or later.
CVE-2023-45101 affects all versions from n/a up to and including 5.36.0 of the CusRev Customer Reviews for WooCommerce plugin.
CVE-2023-45101 exposes the application to unauthorized access, allowing potentially malicious users to exploit the system.
The vendor of the affected software is CusRev, specifically for their Customer Reviews for WooCommerce plugin.