Skip to main content

Vendor/product archive

wpdeveloper / reviewx CVEs

Beta · best-effort

8 CVEs tagged to wpdeveloper / reviewx0 Critical, 2 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2023-40670

Published Dec 13, 2024

Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-43323

Published Nov 1, 2024

Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3609

Published May 16, 2024

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33921

Published May 3, 2024

Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29812

Published Mar 27, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46809

Published Nov 7, 2023

Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2833

Published Jun 6, 2023

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' func…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2023-26325

Published Feb 23, 2023

The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1