Extension WordPress
Vulnérabilités ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
Cette page rassemble les failles publiées pour ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
15 fiches
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.10 – Unauthenticated Stored Cross-Site Scripting
The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.10 due to insufficient input sanitization and output escaping. This makes…
*-2.3.10
2.3.11
01/07/2026
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.6 – Missing Authorization
The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.6. This…
*-2.3.6
2.3.7
22/04/2026
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 – Unauthenticated Sensitive Information Exposure
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes…
*-2.2.12
2.3.0
22/03/2026
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 – Unauthenticated Limited Remote Code Execution
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input…
*-2.2.12
2.3.0
22/03/2026
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 – Unauthenticated Sensitive Information Exposure to Data Export
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes…
*-2.2.12
2.3.0
22/03/2026
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 – Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up…
*-2.2.10
2.2.12
22/03/2026
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.28 – Insufficient Input Validation
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to invalid rating in all versions up to, and including, 1.6.28. This is due to insufficient input validation on the $rating value. This makes…
*-1.6.28
1.6.29
16/08/2024
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 – Missing Authorization
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This…
*-1.6.27
1.6.28
16/05/2024
ReviewX <= 1.6.21 – Missing Authorization
The ReviewX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the remote_post() function in versions up to, and including, 1.6.21. This makes it possible for authenticated attackers, with subscriber-level access and…
*-1.6.21
1.6.22
29/04/2024
ReviewX <= 1.6.22 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ReviewX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.6.22
1.6.23
25/03/2024
ReviewX <= 1.6.17 – Missing Authorization in rx_coupon_from_submit
The ReviewX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rx_coupon_from_submit function in versions up to, and including, 1.6.17. This makes it possible for authenticated attackers, with subscriber-level…
*-1.6.17
1.6.18
22/08/2023
ReviewX <= 1.6.13 – Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a…
*-1.6.13
1.6.14
31/05/2023
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.8 – Authenticated (Subscriber+) SQL Injection
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'filterValue' and 'selectedColumns' parameters passed through the 'rx_export_review' AJAX action in versions up to, and including, 1.6.8 due to…
*-1.6.8
1.6.9
19/04/2023
ReviewX <= 1.6.7 – Unauthenticated CSV Injection
The ReviewX plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.6.7. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files…
*-1.6.7
1.6.8
13/04/2023
WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX < 1.2.9 – Cross-Site Request Forgery
The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2.9. This is due to missing nonce validation in the ~/app/Controllers/Storefront/ReviewxPublic.php file. This makes it possible for…
[*, 1.2.9)
1.2.9
30/06/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.