VYPR
Medium severity5.4NVD Advisory· Published Dec 9, 2024· Updated Apr 28, 2026

CVE-2023-23986

CVE-2023-23986

Description

Missing Authorization vulnerability in Noah Hearle, Design Extreme Reviews and Rating – Google My Business allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reviews and Rating – Google My Business: from n/a through 4.14.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A missing authorization vulnerability in the WordPress Reviews and Rating – Google My Business plugin allows lower-privileged users to perform unauthorized actions.

The WordPress plugin Reviews and Rating – Google My Business (versions prior to 4.15) contains a missing authorization vulnerability [1]. The root cause is that access control checks are improperly configured or missing entirely, allowing users to bypass intended security levels. This flaw is classified as a broken access control issue [1].

Exploitation requires some user interaction, typically a privileged user clicking a malicious link or visiting a crafted page, but can be initiated by an attacker with lower privileges. The attack vector may involve sending a crafted request that exploits the missing authorization check [1]. The vulnerability does not require special network access beyond being able to reach the WordPress admin interface.

Successful exploitation allows an attacker with lower privileges to perform actions that should require higher privilege levels, potentially leading to unauthorized data modification, configuration changes, or other administrative operations. The CVSS score of 5.4 (Medium) reflects this moderate impact [1].

The vendor has released version 4.15 which patches the vulnerability. Users are strongly advised to update immediately. For those who cannot update, Patchstack provides a mitigation rule to block exploitation attempts until the update is applied [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.