VYPR
Unrated severityNVD Advisory· Published Sep 23, 2022· Updated Apr 28, 2026

WordPress Customer Reviews for WooCommerce plugin <= 5.3.5 - Authenticated Broken Access Control vulnerability

CVE-2022-38134

Description

Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated subscribers can exploit broken access control in Customer Reviews for WooCommerce <=5.3.5 to perform unauthorized actions.

Vulnerability

The Customer Reviews for WooCommerce plugin for WordPress, versions 5.3.5 and earlier, contains a broken access control vulnerability. The plugin fails to properly enforce capability checks on certain AJAX endpoints or administrative actions, allowing authenticated users with a subscriber role or higher to access functionality that should be restricted to higher-privileged users like shop managers or administrators [1][2].

Exploitation

An attacker with a valid subscriber account (or any higher role) can craft HTTP requests to the vulnerable endpoints. No additional authentication or user interaction is required beyond having a WordPress account with subscriber privileges. The exact sequence of steps involves sending a specially crafted request to trigger the unauthorized action [2].

Impact

Successful exploitation allows the attacker to perform actions such as modifying review settings, deleting or altering reviews, or accessing sensitive configuration data. The impact is a breach of confidentiality and integrity, potentially leading to loss of control over the review system and exposure of non-public plugin settings [2].

Mitigation

The vulnerability is fixed in version 5.3.6 of the plugin. Users should update to this version or later immediately. No workarounds are available. The plugin is actively maintained, and the vendor has released a patch [1][2].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.