Unauthorized Data Access in ReviewX Plugin for WordPress
CVE-2025-10736
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 March 2026
What is CVE-2025-10736?
The ReviewX plugin for WordPress contains a vulnerability that allows unauthorized users to access sensitive data due to inadequate authorization checks in the userAccessibility() function. This issue affects all versions up to 2.2.10, enabling unauthenticated attackers to exploit protected REST API endpoints, thereby gaining unauthorized access to user data and modifying crucial plugin configurations. Itโs essential for site administrators to address this vulnerability to safeguard their websites from potential data breaches.
Affected Version(s)
ReviewX โ Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema 0 <= 2.2.10