CVE-2025-3063
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 2, 2025
CWE ID 862
Summary
CVE-2025-3063 is a vulnerability affecting the Shopper Approved Reviews plugin for WordPress. The issue lies in the ajax_callback_update_sa_option() function, which lacks necessary capability checks in versions 2.0 to 2.1. This oversight allows authenticated attackers, with Subscriber-level access or higher, to modify arbitrary options on WordPress sites. Successful exploitation of this vulnerability can result in privilege escalation, enabling attackers to update default roles and grant administrative access to themselves.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.