Extension WordPress

Vulnérabilités ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

Cette page rassemble les failles publiées pour ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema, leurs plages de versions affectées et les correctifs signalés dans la base locale.

15Vulnérabilités
0Critiques
15Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

15 fiches

CVE-2026-57359 Élevée · 7,2
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.10 – Unauthenticated Stored Cross-Site Scripting

The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.10 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.3.10

Correctif

2.3.11

Publication

01/07/2026

CVE-2026-40781 Moyenne · 5,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.6 – Missing Authorization

The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.6. This…

Versions affectées

*-2.3.6

Correctif

2.3.7

Publication

22/04/2026

CVE-2025-10734 Moyenne · 5,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 – Unauthenticated Sensitive Information Exposure

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes…

Versions affectées

*-2.2.12

Correctif

2.3.0

Publication

22/03/2026

CVE-2025-10679 Élevée · 7,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 – Unauthenticated Limited Remote Code Execution

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input…

Versions affectées

*-2.2.12

Correctif

2.3.0

Publication

22/03/2026

CVE-2025-10731 Moyenne · 5,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 – Unauthenticated Sensitive Information Exposure to Data Export

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes…

Versions affectées

*-2.2.12

Correctif

2.3.0

Publication

22/03/2026

CVE-2025-10736 Moyenne · 6,5
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 – Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up…

Versions affectées

*-2.2.10

Correctif

2.2.12

Publication

22/03/2026

CVE-2024-43323 Moyenne · 5,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.28 – Insufficient Input Validation

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to invalid rating in all versions up to, and including, 1.6.28. This is due to insufficient input validation on the $rating value. This makes…

Versions affectées

*-1.6.28

Correctif

1.6.29

Publication

16/08/2024

CVE-2024-3609 Moyenne · 4,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 – Missing Authorization

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This…

Versions affectées

*-1.6.27

Correctif

1.6.28

Publication

16/05/2024

CVE-2024-33921 Moyenne · 4,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX <= 1.6.21 – Missing Authorization

The ReviewX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the remote_post() function in versions up to, and including, 1.6.21. This makes it possible for authenticated attackers, with subscriber-level access and…

Versions affectées

*-1.6.21

Correctif

1.6.22

Publication

29/04/2024

CVE-2024-29812 Moyenne · 6,4
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX <= 1.6.22 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ReviewX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-1.6.22

Correctif

1.6.23

Publication

25/03/2024

CVE-2023-40670 Moyenne · 4,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX <= 1.6.17 – Missing Authorization in rx_coupon_from_submit

The ReviewX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rx_coupon_from_submit function in versions up to, and including, 1.6.17. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-1.6.17

Correctif

1.6.18

Publication

22/08/2023

CVE-2023-2833 Élevée · 8,8
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX <= 1.6.13 – Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a…

Versions affectées

*-1.6.13

Correctif

1.6.14

Publication

31/05/2023

CVE-2023-26325 Élevée · 8,8
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.8 – Authenticated (Subscriber+) SQL Injection

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'filterValue' and 'selectedColumns' parameters passed through the 'rx_export_review' AJAX action in versions up to, and including, 1.6.8 due to…

Versions affectées

*-1.6.8

Correctif

1.6.9

Publication

19/04/2023

CVE-2022-46809 Moyenne · 6,5
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

ReviewX <= 1.6.7 – Unauthenticated CSV Injection

The ReviewX plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.6.7. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files…

Versions affectées

*-1.6.7

Correctif

1.6.8

Publication

13/04/2023

Vulnérabilité Élevée · 8,3
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX < 1.2.9 – Cross-Site Request Forgery

The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2.9. This is due to missing nonce validation in the ~/app/Controllers/Storefront/ReviewxPublic.php file. This makes it possible for…

Versions affectées

[*, 1.2.9)

Correctif

1.2.9

Publication

30/06/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités