OVERVIEW The Customer Reviews for WooCommerce plugin for WordPress versions up to 5.103.0 contains an authentication bypass vulnerability in its review submission REST API endpoint. The flaw exists in the create_review_permissions_check() function, which fails to validate that stored authentication keys are non-empty before comparison. This allows unauthenticated attackers to bypass permission controls and submit, modify, or inject product reviews via the POST /ivole/v1/review endpoint. SEVERITY The vulnerability is network-accessible with low attack complexity and requires no user interaction or authentication, making it easily exploitable by remote attackers. The CVSS v3.1 score of 5.3 (MEDIUM) reflects limited integrity impact, as the primary risk involves unauthorized review creation and modification. The attack surface is particularly concerning because reviews are auto-approved by default, enabling attackers to inject malicious or defamatory content immediately without administrator review. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and has not been added to any hot list tracking. However, the FAUCET risk score of 41.0/100 and relatively straightforward exploitation method suggest organizations should apply patches promptly to prevent potential abuse. Community attention remains minimal at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Ivole | Customer Reviews For WooCommerce | >= 0, <= 5.103.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.