plugin

Reviewx Vulnerabilities

27 known security issues reported for the Reviewx WordPress plugin. Most recent disclosed Jul 1, 2026.

5 high 12 medium

Running Reviewx on your site? Check whether your installed version is affected.

Scan your site free

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.10 - Unauthenticated Stored Cross-Site Scripting

high

The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
7.2
Affected:
up to 2.3.10
Fixed in:
2.3.11
Disclosed:
Jul 1, 2026

CVE-2026-57359 on NVD →

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.6 - Missing Authorization

medium

The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.3.6
Fixed in:
2.3.7
Disclosed:
Apr 22, 2026

CVE-2026-40781 on NVD →

ReviewX - WordPress ReviewX - WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation vulnerability

medium

WordPress ReviewX - WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation vulnerability

CVSS:
6.5
Affected:
up to 2.2.10
Fixed in:
2.2.12
Disclosed:
Mar 24, 2026

ReviewX - WordPress ReviewX - WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin <= 2.2.12 - Unauthenticated Sensitive Information Exposure vulnerability

medium

WordPress ReviewX - WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin <= 2.2.12 - Unauthenticated Sensitive Information Exposure vulnerability

CVSS:
5.3
Affected:
up to 2.2.12
Fixed in:
2.3.0
Disclosed:
Mar 23, 2026

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure

medium

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible for unauthenticated attackers to extract sen...

CVSS:
5.3
Affected:
up to 2.2.12
Fixed in:
2.3.0
Disclosed:
Mar 22, 2026

CVE-2025-10734 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution

high

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input validation in the bulkTenReviews function that allows user-controlled...

CVSS:
7.3
Affected:
up to 2.2.12
Fixed in:
2.3.0
Disclosed:
Mar 22, 2026

CVE-2025-10679 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure to Data Export

medium

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes it possible for unauthenticated attackers to ob...

CVSS:
5.3
Affected:
up to 2.2.12
Fixed in:
2.3.0
Disclosed:
Mar 22, 2026

CVE-2025-10731 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation

medium

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up to, and including, 2.2.10. This makes it possible fo...

CVSS:
6.5
Affected:
up to 2.2.10
Fixed in:
2.2.12
Disclosed:
Mar 22, 2026

CVE-2025-10736 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.6.18

unknown

[en] Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17.

Affected:
up to 1.6.18
Fixed in:
1.6.18
Disclosed:
Dec 13, 2024

CVE-2023-40670 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.6.29

unknown

[en] Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.

Affected:
up to 1.6.29
Fixed in:
1.6.29
Disclosed:
Nov 1, 2024

CVE-2024-43323 on NVD →

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.28 - Insufficient Input Validation

medium

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to invalid rating in all versions up to, and including, 1.6.28. This is due to insufficient input validation on the $rating value. This makes it possible for unauthenticated attackers to provide ratings with invalid data.

CVSS:
5.3
Affected:
up to 1.6.28
Fixed in:
1.6.29
Disclosed:
Aug 16, 2024

CVE-2024-43323 on NVD →

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization

medium

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber...

CVSS:
4.3
Affected:
up to 1.6.27
Fixed in:
1.6.28
Disclosed:
May 16, 2024

CVE-2024-3609 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.6.28

unknown

[en] The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subsc...

Affected:
up to 1.6.28
Fixed in:
1.6.28
Disclosed:
May 16, 2024

CVE-2024-3609 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.6.22

unknown

[en] Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.

Affected:
up to 1.6.22
Fixed in:
1.6.22
Disclosed:
May 3, 2024

CVE-2024-33921 on NVD →

ReviewX <= 1.6.21 - Missing Authorization

medium

The ReviewX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the remote_post() function in versions up to, and including, 1.6.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform a post request.

CVSS:
4.3
Affected:
up to 1.6.21
Fixed in:
1.6.22
Disclosed:
Apr 29, 2024

CVE-2024-33921 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.6.23

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.

Affected:
up to 1.6.23
Fixed in:
1.6.23
Disclosed:
Mar 27, 2024

CVE-2024-29812 on NVD →

ReviewX <= 1.6.22 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ReviewX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 1.6.22
Fixed in:
1.6.23
Disclosed:
Mar 25, 2024

CVE-2024-29812 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.6.8

unknown

[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.

Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
Nov 7, 2023

CVE-2022-46809 on NVD →

ReviewX <= 1.6.17 - Missing Authorization in rx_coupon_from_submit

medium

The ReviewX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rx_coupon_from_submit function in versions up to, and including, 1.6.17. This makes it possible for authenticated attackers, with subscriber-level access and above, to update options.

CVSS:
4.3
Affected:
up to 1.6.17
Fixed in:
1.6.18
Disclosed:
Aug 22, 2023

CVE-2023-40670 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.6.14

unknown

[en] The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by su...

Affected:
up to 1.6.14
Fixed in:
1.6.14
Disclosed:
Jun 6, 2023

CVE-2023-2833 on NVD →

ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

high

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplyi...

CVSS:
8.8
Affected:
up to 1.6.13
Fixed in:
1.6.14
Disclosed:
May 31, 2023

CVE-2023-2833 on NVD →

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.8 - Authenticated (Subscriber+) SQL Injection

high

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'filterValue' and 'selectedColumns' parameters passed through the 'rx_export_review' AJAX action in versions up to, and including, 1.6.8 due to insufficient escaping on the user supplied parameter a...

CVSS:
8.8
Affected:
up to 1.6.8
Fixed in:
1.6.9
Disclosed:
Apr 19, 2023

CVE-2023-26325 on NVD →

ReviewX <= 1.6.7 - Unauthenticated CSV Injection

medium

The ReviewX plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.6.7. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration...

CVSS:
6.5
Affected:
up to 1.6.7
Fixed in:
1.6.8
Disclosed:
Apr 13, 2023

CVE-2022-46809 on NVD →

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.6.9

unknown

[en] The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.

Affected:
up to 1.6.9
Fixed in:
1.6.9
Disclosed:
Feb 23, 2023

CVE-2023-26325 on NVD →

WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX < 1.2.9 - Cross-Site Request Forgery

high

The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2.9. This is due to missing nonce validation in the ~/app/Controllers/Storefront/ReviewxPublic.php file. This makes it possible for unauthenticated attackers to perf...

CVSS:
8.3
Affected:
up to 1.2.9
Fixed in:
1.2.9
Disclosed:
Jun 30, 2021

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.2.9

unknown

The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2.9. This is due to missing nonce validation in the ~/app/Controllers/Storefront/ReviewxPublic.php file. This makes it possible for unauthenticated attackers to perf...

Affected:
up to 1.2.9
Fixed in:
1.2.9
Disclosed:
Jun 30, 2021

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema &amp; More [reviewx] < 1.2.9

unknown

Some of the plugin AJAX actions did not properly check for CRSF nonce, allowing attacker to make users call them and perform unwanted actions.

Affected:
up to 1.2.9
Fixed in:
1.2.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database