CyberRota Analysis
AI-GeneratedThe Customer Reviews for WooCommerce plugin for WordPress prior to version 5.116.0 is vulnerable due to a lack of nonce and capability checks on certain AJAX actions, enabling users with minimal permissions, like Subscribers, to access and modify administrative settings. This could lead to unauthorized changes in plugin options and potential exposure of sensitive store configuration data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.