CVE-2023-40670
- EPSS 0.12%
- Published 13.12.2024 15:15:22
- Last modified 27.06.2025 18:08:45
Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17.
CVE-2024-43323
- EPSS 0.22%
- Published 01.11.2024 15:15:47
- Last modified 19.11.2024 18:15:20
Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.
CVE-2024-3609
- EPSS 0.22%
- Published 16.05.2024 21:16:10
- Last modified 27.06.2025 18:08:33
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.2...
CVE-2024-33921
- EPSS 0.14%
- Published 03.05.2024 09:15:09
- Last modified 10.06.2025 18:03:40
Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.
CVE-2024-29812
- EPSS 0.18%
- Published 27.03.2024 13:15:53
- Last modified 13.05.2025 16:02:50
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.
CVE-2022-46809
- EPSS 0.69%
- Published 07.11.2023 17:15:09
- Last modified 21.11.2024 07:31:05
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.
CVE-2023-2833
- EPSS 25.63%
- Published 06.06.2023 10:15:09
- Last modified 21.11.2024 07:59:22
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal ...
CVE-2023-26325
- EPSS 0.5%
- Published 23.02.2023 20:15:14
- Last modified 21.11.2024 07:51:07
The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.