CVE-2023-2833

HIGH

ReviewX plugin <1.6.13 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_screen_options[option]' and 'wp_screen_options[value]' parameters during a screen option update.

Exploits (1)

nomisec SUSPICIOUS 1 stars
by Alucard0x1 · poc
https://github.com/Alucard0x1/CVE-2023-2833

Scores

CVSS v3 8.8
EPSS 0.2679
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
reviewx/ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema < 1.6.13
wpdeveloper/reviewx < 1.6.13
Published Jun 06, 2023
Tracked Since Feb 18, 2026