Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2023-40670
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17.
0
Attacker Value
Unknown
CVE-2024-43323
Disclosure Date: November 01, 2024 (last updated November 19, 2024)
Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.
0
Attacker Value
Unknown
CVE-2024-3609
Disclosure Date: May 16, 2024 (last updated January 05, 2025)
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber access and above, to delete attachments.
0
Attacker Value
Unknown
CVE-2024-33921
Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.
0
Attacker Value
Unknown
CVE-2024-29812
Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.
0
Attacker Value
Unknown
CVE-2022-46809
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7.
0
Attacker Value
Unknown
CVE-2023-2833
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_screen_options[option]' and 'wp_screen_options[value]' parameters during a screen option update.
0
Attacker Value
Unknown
CVE-2023-26325
Disclosure Date: February 23, 2023 (last updated October 08, 2023)
The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.
0