Executive brief
ReviewX, a WordPress plugin used for managing customer reviews, contains a security flaw that allows unauthorized individuals to bypass authentication. An attacker could exploit this to perform actions typically reserved for administrators, potentially leading to a full takeover of the website. This could result in the loss of site control, unauthorized content changes, or disruption of business operations.
Technical details
ReviewX versions up to and including 2.3.6 are vulnerable to an authentication bypass (CWE-288) via an alternate path or channel. The vulnerability allows an unauthenticated remote attacker to bypass security checks and perform actions that should be restricted to high-privileged users. According to the advisory, this could lead to unauthorized administrative access to the WordPress site. The issue is resolved in version 2.3.7. The attack vector is network-based with low complexity and requires no user interaction or prior privileges.
Affected products
- ReviewX ReviewX <= 2.3.6
Timeline
- 2026-03-11: other: Reported by Jakub Herman
- 2026-04-22: advisory: Initial Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date