Unauthorized Data Modification in WordPress Review Schema Plugin
CVE-2024-0836
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 January 2024
What is CVE-2024-0836?
The Review Schema plugin for WordPress is susceptible to unauthorized data modification due to a lack of necessary capability checks within the rtrs_review_edit() function. This vulnerability affects all versions up to and including 2.1.14, allowing authenticated attackers with subscriber-level access and above to alter any review data. This exploitation can compromise the integrity of review information, potentially misleading users and affecting the overall reliability of the site.
Affected Version(s)
Review Schema β Review & Structure Data Schema Plugin 0 <= 2.1.14