PT-2026-27047 · WordPress+1 · Reviewx+1

Abrahack

·

Publicado

2026-03-23

·

Atualizado

2026-03-23

·

CVE-2025-10679

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress versions through 2.2.12
Description The ReviewX plugin for WordPress is susceptible to arbitrary method calls due to inadequate input validation within the bulkTenReviews function. This allows attackers to pass user-controlled data to a variable function call, potentially enabling the execution of arbitrary PHP class methods that require no inputs or have default values. Successful exploitation could lead to information disclosure or remote code execution, contingent upon the server configuration and available methods.
Recommendations Update the ReviewX plugin to a version newer than 2.2.12.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-10679

Produtos afetados

Reviewx
Woocommerce