Plugin Vulnerability Hub
Plugin 13 known issues Latest disclosed Mar 22, 2026

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Vulnerabilities

Review known vulnerability records for the WordPress plugin ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema (`reviewx`), including severity, CVE references, affected versions, and patch status.

Known Records
13
High or Critical
4
Linked CVEs
12
Last Updated
Mar 22, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
13 records include a published patch path.
Severity Mix
0 critical and 4 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-10734
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible for...

Published
Mar 22, 2026
Patched Release
2.3.0
Affected Versions
Versions up to 2.2.12
Next Step
Update to 2.3.0 or newer if supported.
Plugin High Patched: Yes CVE-2025-10679
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input validation in the bulkTenRevi...

Published
Mar 22, 2026
Patched Release
2.3.0
Affected Versions
Versions up to 2.2.12
Next Step
Update to 2.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-10731
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure to Data Export

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes it poss...

Published
Mar 22, 2026
Patched Release
2.3.0
Affected Versions
Versions up to 2.2.12
Next Step
Update to 2.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-10736
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up to, and incl...

Published
Mar 22, 2026
Patched Release
2.2.12
Affected Versions
Versions up to 2.2.10
Next Step
Update to 2.2.12 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-43323
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.28 - Insufficient Input Validation

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to invalid rating in all versions up to, and including, 1.6.28. This is due to insufficient input validation on the $rating value. This makes it possible for unauthenticated attackers...

Published
Aug 16, 2024
Patched Release
1.6.29
Affected Versions
Versions up to 1.6.28
Next Step
Update to 1.6.29 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3609
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for...

Published
May 16, 2024
Patched Release
1.6.28
Affected Versions
Versions up to 1.6.27
Next Step
Update to 1.6.28 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-33921
ReviewX <= 1.6.21 - Missing Authorization

The ReviewX plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the remote_post() function in versions up to, and including, 1.6.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform a...

Published
Apr 29, 2024
Patched Release
1.6.22
Affected Versions
Versions up to 1.6.21
Next Step
Update to 1.6.22 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-29812
ReviewX <= 1.6.22 - Authenticated (Contributor+) Stored Cross-Site Scripting

The ReviewX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...

Published
Mar 25, 2024
Patched Release
1.6.23
Affected Versions
Versions up to 1.6.22
Next Step
Update to 1.6.23 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-40670
ReviewX <= 1.6.17 - Missing Authorization in rx_coupon_from_submit

The ReviewX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rx_coupon_from_submit function in versions up to, and including, 1.6.17. This makes it possible for authenticated attackers, with subscriber-level access a...

Published
Aug 22, 2023
Patched Release
1.6.18
Affected Versions
Versions up to 1.6.17
Next Step
Update to 1.6.18 or newer if supported.
Plugin High Patched: Yes CVE-2023-2833
ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscrib...

Published
May 31, 2023
Patched Release
1.6.14
Affected Versions
Versions up to 1.6.13
Next Step
Update to 1.6.14 or newer if supported.
Plugin High Patched: Yes CVE-2023-26325
ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.8 - Authenticated (Subscriber+) SQL Injection

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'filterValue' and 'selectedColumns' parameters passed through the 'rx_export_review' AJAX action in versions up to, and including, 1.6.8 due to insufficient e...

Published
Apr 19, 2023
Patched Release
1.6.9
Affected Versions
Versions up to 1.6.8
Next Step
Update to 1.6.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-46809
ReviewX <= 1.6.7 - Unauthenticated CSV Injection

The ReviewX plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.6.7. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a loca...

Published
Apr 13, 2023
Patched Release
1.6.8
Affected Versions
Versions up to 1.6.7
Next Step
Update to 1.6.8 or newer if supported.