PT-2026-27047 · WordPress+1 · Reviewx+1
Abrahack
·
Published
2026-03-23
·
Updated
2026-03-23
·
CVE-2025-10679
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress versions through 2.2.12
Description
The ReviewX plugin for WordPress is susceptible to arbitrary method calls due to inadequate input validation within the
bulkTenReviews function. This allows attackers to pass user-controlled data to a variable function call, potentially enabling the execution of arbitrary PHP class methods that require no inputs or have default values. Successful exploitation could lead to information disclosure or remote code execution, contingent upon the server configuration and available methods.Recommendations
Update the ReviewX plugin to a version newer than 2.2.12.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Reviewx
Woocommerce