# Site Reviews <= 8.3.3 - Authenticated (Subscriber+) Missing Authorization to User Information Exposure via REST Shortcode Options Endpoint

- **ID:** WPSEC-2026-0434
- **Plugin:** Site Reviews (`site-reviews`), https://wordpress.org/plugins/site-reviews/
- **Affected versions:** all versions before 8.3.4
- **Fixed in:** 8.3.4 (Update to 8.3.4 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-05)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/site-reviews
- **Fix released:** 2026-10-04
- **Published:** 2026-10-05
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0434/

## Description

The Site Reviews plugin for WordPress is vulnerable to unauthorized access of data via the REST API shortcode options route in all versions up to, and including, 8.3.3 due to a missing capability check in the checkShortcodePermission function, which only verified that the requester was logged in. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve the shortcode option lists, which include the site's users, and thereby enumerate user names regardless of their role.

## References

- https://wpsec.com/vuln/WPSEC-2026-0434/
- https://plugins.svn.wordpress.org/site-reviews/tags/8.3.4/
- https://wordpress.org/plugins/site-reviews/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0434/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
