ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx · plugin
Known security vulnerabilities for ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema. Find out in seconds which version runs on your site with WP Lens.
13 known vulnerabilities
2 critical · 8 exploitable without logging in · 1 with public exploit code · latest Jul 2, 2026
Listed on wordpress.org · latest 2.5.1 · last updated Aug 31, 2026 · 7K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2024-43323unauthenticated≤ 1.6.28
WordPress ReviewX plugin <= 1.6.28 - Broken Access Control vulnerability
- Critical 9.8
CVE-2022-46809unauthenticated · needs a click≤ 1.6.7
WordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV Injection
- High 8.8
CVE-2024-33921login required≤ 1.6.21
WordPress ReviewX plugin <= 1.6.21 - Broken Access Control vulnerability
- High 8.8
CVE-2023-2833subscriber+≤ 1.6.13
ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
- High 7.5
CVE-2026-40781unauthenticated≤ 2.3.6
WordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerability
- High 7.3
CVE-2025-10679unauthenticated≤ 2.2.12
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execut
- High 7.1
CVE-2026-57359unauthenticated · needs a click≤ 2.3.10
WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2025-10736unauthenticated≤ 2.2.10
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated
- Medium 5.4
CVE-2024-29812login required≤ 1.6.22
WordPress ReviewX plugin <= 1.6.22 - Cross Site Scripting (XSS) vulnerability
- Medium 5.3
CVE-2025-10734unauthenticated≤ 2.2.12
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Expo
- Medium 5.3
CVE-2025-10731unauthenticated≤ 2.2.12
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Expo
- Medium 4.3
CVE-2023-40670login required≤ 1.6.17
WordPress ReviewX plugin <= 1.6.17 - Broken Access Control vulnerability
- Medium 4.3
CVE-2024-3609subscriber+≤ 1.6.27
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).