Vulnerabilities / Site Reviews / WPSEC-2026-0434

Site Reviews <= 8.3.3 - Authenticated (Subscriber+) Missing Authorization to User Information Exposure via REST Shortcode Options Endpoint

Medium 4.3 CWE-862Fixed in 8.3.4
ID
WPSEC-2026-0434
Plugin
Site Reviews (site-reviews)
Affected
all versions before 8.3.4
Remediation
Update to 8.3.4 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-05
Attack surface
Site Reviews on WPSec AttackSurface
Fix released
Published

Description

The Site Reviews plugin for WordPress is vulnerable to unauthorized access of data via the REST API shortcode options route in all versions up to, and including, 8.3.3 due to a missing capability check in the checkShortcodePermission function, which only verified that the requester was logged in. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve the shortcode option lists, which include the site's users, and thereby enumerate user names regardless of their role.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0