PT-2026-27047 · WordPress+1 · Reviewx+1

Abrahack

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2025-10679

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress versions through 2.2.12
Description The ReviewX plugin for WordPress is susceptible to arbitrary method calls due to inadequate input validation within the bulkTenReviews function. This allows attackers to pass user-controlled data to a variable function call, potentially enabling the execution of arbitrary PHP class methods that require no inputs or have default values. Successful exploitation could lead to information disclosure or remote code execution, contingent upon the server configuration and available methods.
Recommendations Update the ReviewX plugin to a version newer than 2.2.12.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10679

Affected Products

Reviewx
Woocommerce