CVE-2026-97280: WordPress Review Schema plugin 3.1.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Review Schema: 3.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Review Schema pluginto a version that resolves this vulnerability.Fixed in 3.1.1
Event History
Frequently Asked Questions
Which installations are known to be affected?
The affected product is Mamunur Rashid Review Schema for WordPress, specifically version 3.1.0. No other affected or fixed versions are identified in the provided data.
Does exploitation require an authenticated WordPress account or user interaction?
No. The vector indicates network exploitation with no privileges required and no user interaction required, so an unauthenticated remote attacker may be able to exploit the issue.
What security impact is indicated?
The supplied CVSS vector indicates no confidentiality impact, with low integrity and availability impact. The reported severity is medium, with a score of 6.5.