Skip to content
Noroxi

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

reviewx · plugin

Known security vulnerabilities for ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema. Find out in seconds which version runs on your site with WP Lens.

13 known vulnerabilities

2 critical · 8 exploitable without logging in · 1 with public exploit code · latest Jul 2, 2026

Listed on wordpress.org · latest 2.5.1 · last updated Aug 31, 2026 · 7K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2024-43323unauthenticated≤ 1.6.28

    WordPress ReviewX plugin <= 1.6.28 - Broken Access Control vulnerability

    Critical 9.8
  • CVE-2022-46809unauthenticated · needs a click≤ 1.6.7

    WordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV Injection

    Critical 9.8
  • CVE-2024-33921login required≤ 1.6.21

    WordPress ReviewX plugin <= 1.6.21 - Broken Access Control vulnerability

    High 8.8
  • CVE-2023-2833subscriber+≤ 1.6.13

    ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

    High 8.8
  • CVE-2026-40781unauthenticated≤ 2.3.6

    WordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerability

    High 7.5
  • CVE-2025-10679unauthenticated≤ 2.2.12

    ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execut

    High 7.3
  • CVE-2026-57359unauthenticated · needs a click≤ 2.3.10

    WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2025-10736unauthenticated≤ 2.2.10

    ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated

    Medium 6.5
  • CVE-2024-29812login required≤ 1.6.22

    WordPress ReviewX plugin <= 1.6.22 - Cross Site Scripting (XSS) vulnerability

    Medium 5.4
  • CVE-2025-10734unauthenticated≤ 2.2.12

    ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Expo

    Medium 5.3
  • CVE-2025-10731unauthenticated≤ 2.2.12

    ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Expo

    Medium 5.3
  • CVE-2023-40670login required≤ 1.6.17

    WordPress ReviewX plugin <= 1.6.17 - Broken Access Control vulnerability

    Medium 4.3
  • CVE-2024-3609subscriber+≤ 1.6.27

    ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory