ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.10 - Unauthenticated Stored Cross-Site Scripting
high
The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 7.2
- Affected:
- up to 2.3.10
- Fixed in:
- 2.3.11
- Disclosed:
- Jul 1, 2026
CVE-2026-57359 on NVD →
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.6 - Missing Authorization
medium
The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.3.6
- Fixed in:
- 2.3.7
- Disclosed:
- Apr 22, 2026
CVE-2026-40781 on NVD →
ReviewX - WordPress ReviewX - WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation vulnerability
medium
WordPress ReviewX - WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation vulnerability
- CVSS:
- 6.5
- Affected:
- up to 2.2.10
- Fixed in:
- 2.2.12
- Disclosed:
- Mar 24, 2026
ReviewX - WordPress ReviewX - WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin <= 2.2.12 - Unauthenticated Sensitive Information Exposure vulnerability
medium
WordPress ReviewX - WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin <= 2.2.12 - Unauthenticated Sensitive Information Exposure vulnerability
- CVSS:
- 5.3
- Affected:
- up to 2.2.12
- Fixed in:
- 2.3.0
- Disclosed:
- Mar 23, 2026
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure
medium
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible for unauthenticated attackers to extract sen...
- CVSS:
- 5.3
- Affected:
- up to 2.2.12
- Fixed in:
- 2.3.0
- Disclosed:
- Mar 22, 2026
CVE-2025-10734 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution
high
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input validation in the bulkTenReviews function that allows user-controlled...
- CVSS:
- 7.3
- Affected:
- up to 2.2.12
- Fixed in:
- 2.3.0
- Disclosed:
- Mar 22, 2026
CVE-2025-10679 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure to Data Export
medium
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes it possible for unauthenticated attackers to ob...
- CVSS:
- 5.3
- Affected:
- up to 2.2.12
- Fixed in:
- 2.3.0
- Disclosed:
- Mar 22, 2026
CVE-2025-10731 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation
medium
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up to, and including, 2.2.10. This makes it possible fo...
- CVSS:
- 6.5
- Affected:
- up to 2.2.10
- Fixed in:
- 2.2.12
- Disclosed:
- Mar 22, 2026
CVE-2025-10736 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.6.18
unknown
[en] Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17.
- Affected:
- up to 1.6.18
- Fixed in:
- 1.6.18
- Disclosed:
- Dec 13, 2024
CVE-2023-40670 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.6.29
unknown
[en] Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.
- Affected:
- up to 1.6.29
- Fixed in:
- 1.6.29
- Disclosed:
- Nov 1, 2024
CVE-2024-43323 on NVD →
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.28 - Insufficient Input Validation
medium
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to invalid rating in all versions up to, and including, 1.6.28. This is due to insufficient input validation on the $rating value. This makes it possible for unauthenticated attackers to provide ratings with invalid data.
- CVSS:
- 5.3
- Affected:
- up to 1.6.28
- Fixed in:
- 1.6.29
- Disclosed:
- Aug 16, 2024
CVE-2024-43323 on NVD →
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization
medium
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber...
- CVSS:
- 4.3
- Affected:
- up to 1.6.27
- Fixed in:
- 1.6.28
- Disclosed:
- May 16, 2024
CVE-2024-3609 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.6.28
unknown
[en] The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subsc...
- Affected:
- up to 1.6.28
- Fixed in:
- 1.6.28
- Disclosed:
- May 16, 2024
CVE-2024-3609 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.6.22
unknown
[en] Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.
- Affected:
- up to 1.6.22
- Fixed in:
- 1.6.22
- Disclosed:
- May 3, 2024
CVE-2024-33921 on NVD →
ReviewX <= 1.6.21 - Missing Authorization
medium
The ReviewX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the remote_post() function in versions up to, and including, 1.6.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform a post request.
- CVSS:
- 4.3
- Affected:
- up to 1.6.21
- Fixed in:
- 1.6.22
- Disclosed:
- Apr 29, 2024
CVE-2024-33921 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.6.23
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.
- Affected:
- up to 1.6.23
- Fixed in:
- 1.6.23
- Disclosed:
- Mar 27, 2024
CVE-2024-29812 on NVD →
ReviewX <= 1.6.22 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ReviewX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 1.6.22
- Fixed in:
- 1.6.23
- Disclosed:
- Mar 25, 2024
CVE-2024-29812 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.6.8
unknown
[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Nov 7, 2023
CVE-2022-46809 on NVD →
ReviewX <= 1.6.17 - Missing Authorization in rx_coupon_from_submit
medium
The ReviewX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rx_coupon_from_submit function in versions up to, and including, 1.6.17. This makes it possible for authenticated attackers, with subscriber-level access and above, to update options.
- CVSS:
- 4.3
- Affected:
- up to 1.6.17
- Fixed in:
- 1.6.18
- Disclosed:
- Aug 22, 2023
CVE-2023-40670 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.6.14
unknown
[en] The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by su...
- Affected:
- up to 1.6.14
- Fixed in:
- 1.6.14
- Disclosed:
- Jun 6, 2023
CVE-2023-2833 on NVD →
ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
high
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplyi...
- CVSS:
- 8.8
- Affected:
- up to 1.6.13
- Fixed in:
- 1.6.14
- Disclosed:
- May 31, 2023
CVE-2023-2833 on NVD →
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.8 - Authenticated (Subscriber+) SQL Injection
high
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'filterValue' and 'selectedColumns' parameters passed through the 'rx_export_review' AJAX action in versions up to, and including, 1.6.8 due to insufficient escaping on the user supplied parameter a...
- CVSS:
- 8.8
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.9
- Disclosed:
- Apr 19, 2023
CVE-2023-26325 on NVD →
ReviewX <= 1.6.7 - Unauthenticated CSV Injection
medium
The ReviewX plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.6.7. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration...
- CVSS:
- 6.5
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.8
- Disclosed:
- Apr 13, 2023
CVE-2022-46809 on NVD →
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.6.9
unknown
[en] The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.
- Affected:
- up to 1.6.9
- Fixed in:
- 1.6.9
- Disclosed:
- Feb 23, 2023
CVE-2023-26325 on NVD →
WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX < 1.2.9 - Cross-Site Request Forgery
high
The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2.9. This is due to missing nonce validation in the ~/app/Controllers/Storefront/ReviewxPublic.php file. This makes it possible for unauthenticated attackers to perf...
- CVSS:
- 8.3
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
- Disclosed:
- Jun 30, 2021
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.2.9
unknown
The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2.9. This is due to missing nonce validation in the ~/app/Controllers/Storefront/ReviewxPublic.php file. This makes it possible for unauthenticated attackers to perf...
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
- Disclosed:
- Jun 30, 2021
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More [reviewx] < 1.2.9
unknown
Some of the plugin AJAX actions did not properly check for CRSF nonce, allowing attacker to make users call them and perform unwanted actions.
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9