Wpdeveloper
Wpdeveloper Reviewx: vulnerabilidades y CVE
Wpdeveloper Reviewx tiene 14 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses6
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57359 | Alta (7.1) | 0.25% | — | 2 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions. |
| CVE-2026-40781 | Alta (7.5) | 0.43% | — | 15 jun 2026 | Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions. |
| CVE-2025-10734 | Media (5.3) | 0.22% | — | 23 mar 2026 | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… |
| CVE-2025-10731 | Media (5.3) | 0.31% | — | 23 mar 2026 | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… |
| CVE-2025-10679 | Alta (7.3) | 0.45% | — | 23 mar 2026 | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12.… |
| CVE-2025-10736 | Media (6.5) | 0.17% | — | 23 mar 2026 | The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the… |
| CVE-2023-40670 | Media (4.3) | 0.48% | — | 13 dic 2024 | Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17. |
| CVE-2024-43323 | Crítica (9.8) | 0.48% | — | 1 nov 2024 | Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28. |
| CVE-2024-3609 | Media (4.3) | 0.37% | — | 16 may 2024 | The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all… |
| CVE-2024-33921 | Alta (8.8) | 0.40% | — | 3 may 2024 | Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21. |
| CVE-2024-29812 | Media (5.4) | 0.36% | — | 27 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22. |
| CVE-2022-46809 | Crítica (9.8) | 0.79% | — | 7 nov 2023 | Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for… |
| CVE-2023-2833 | Alta (8.8) | 17% | — | 6 jun 2023 | The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for… |
| CVE-2023-26325 | Alta (8.8) | 0.87% | — | 23 feb 2023 | The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.