Unauthorized Data Access in ReviewX Plugin for WordPress
CVE-2025-10736

6.5MEDIUM

What is CVE-2025-10736?

The ReviewX plugin for WordPress contains a vulnerability that allows unauthorized users to access sensitive data due to inadequate authorization checks in the userAccessibility() function. This issue affects all versions up to 2.2.10, enabling unauthenticated attackers to exploit protected REST API endpoints, thereby gaining unauthorized access to user data and modifying crucial plugin configurations. Itโ€™s essential for site administrators to address this vulnerability to safeguard their websites from potential data breaches.

Affected Version(s)

ReviewX โ€“ Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema 0 <= 2.2.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

abrahack
.