plugin

Reviews Plus Vulnerabilities

2 known security issues reported for the Reviews Plus WordPress plugin. Most recent disclosed Apr 22, 2024.

2 medium

Running Reviews Plus on your site? Check whether your installed version is affected.

Scan your site free

Reviews Plus <= 1.3.4 - Missing Authorization to Notice Dismissal

medium

The Reviews Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_hide_revs_translation_notice() function in versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss n...

CVSS:
4.3
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
Apr 22, 2024

CVE-2024-32822 on NVD →

Reviews Plus < 1.2.14 - Denial of Service

medium

The Reviews Plus plugin for WordPress is vulnerable to Denial of Service in versions before 1.2.14. This is due to an unknown part of the file post/page of the component Rating Submission Handler. The manipulation with an unknown input leads to a denial of service vulnerability. This makes it possible for authenticatio...

CVSS:
6.5
Affected:
up to 1.2.14
Fixed in:
1.2.15
Disclosed:
Oct 25, 2021

CVE-2021-24894 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database