CVE-2026-97282: WordPress Review Schema plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.
Affected Software
1 affected component
WordPress Review Schema plugin<=3.1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Review Schema pluginto a version that resolves this vulnerability.Fixed in 3.1.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated WordPress account or user interaction?
No. The vulnerability is rated with no privileges required and no user interaction required, so an unauthenticated remote attacker could attempt exploitation over the network.
2
What is the expected security impact?
The reported impact is limited to integrity. Confidentiality and availability impact are rated as none, while integrity impact is rated low.