Wpdeveloper

Reviewx

8 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Published 13.12.2024 15:15:22
  • Last modified 27.06.2025 18:08:45

Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17.

  • EPSS 0.22%
  • Published 01.11.2024 15:15:47
  • Last modified 19.11.2024 18:15:20

Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.

  • EPSS 0.22%
  • Published 16.05.2024 21:16:10
  • Last modified 27.06.2025 18:08:33

The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.2...

  • EPSS 0.14%
  • Published 03.05.2024 09:15:09
  • Last modified 10.06.2025 18:03:40

Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.

  • EPSS 0.18%
  • Published 27.03.2024 13:15:53
  • Last modified 13.05.2025 16:02:50

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.

  • EPSS 0.69%
  • Published 07.11.2023 17:15:09
  • Last modified 21.11.2024 07:31:05

Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.

Exploit
  • EPSS 25.63%
  • Published 06.06.2023 10:15:09
  • Last modified 21.11.2024 07:59:22

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal ...

Exploit
  • EPSS 0.5%
  • Published 23.02.2023 20:15:14
  • Last modified 21.11.2024 07:51:07

The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.