CVE-2025-10731
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-10731 is a Sensitive Information Exposure vulnerability in the ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress. It affects all versions up to and including 2.2.12, and was published on March 23, 2026, with Wordfence credited as the assigner. The flaw allows unauthenticated attackers to obtain authentication tokens via the allReminderSettings function, subsequently bypassing admin restrictions to access and export sensitive customer data. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-285 (Improper Authorization). The allReminderSettings function in the plugin's REST API does not enforce proper authentication checks, allowing unauthenticated HTTP requests to retrieve authentication tokens. These tokens can then be used to bypass the AdminMiddleware access controls and invoke privileged endpoints such as those in DataSyncController, enabling export of sensitive store data. The vulnerable code paths are visible in the plugin's source at EmailTemplateController.php, AdminMiddleware.php, and DataSyncController.php (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated remote attackers to obtain admin-level authentication tokens and access sensitive WooCommerce store data, including order details, customer names, email addresses, physical addresses, phone numbers, and user account information. The impact is primarily a confidentiality breach (no integrity or availability impact), but the exposed data could facilitate phishing campaigns, identity theft, or further targeted attacks against store customers and administrators (Wordfence, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.093%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and low complexity, making it straightforward to exploit if a proof-of-concept is published (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the ReviewX plugin (versions ≤ 2.2.12) using tools like WPScan, Shodan, or by checking /wp-content/plugins/reviewx/ for plugin presence.
  2. Unauthenticated token retrieval: Send an unauthenticated HTTP GET or POST request to the REST API endpoint that invokes the allReminderSettings function (e.g., /wp-json/reviewx/v1/...) to retrieve an authentication token exposed in the response.
  3. Bypass admin middleware: Use the obtained token in subsequent API requests to endpoints protected by AdminMiddleware, effectively impersonating an admin user.
  4. Data exfiltration: Call the DataSyncController export endpoint with the token to download sensitive WooCommerce data including order details, customer names, emails, addresses, and phone numbers (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to ReviewX REST API endpoints (e.g., /wp-json/reviewx/v1/) from unknown IP addresses, particularly those fetching reminder settings or triggering data sync/export operations.
  • Logs: WordPress access logs showing repeated unauthenticated requests to ReviewX REST API routes followed by requests to admin-restricted endpoints using the same session or token; HTTP 200 responses to endpoints that should require authentication.
  • File System: No file-system artifacts expected for this vulnerability, as exploitation is purely API-based.
  • Process/Application: Unexpected bulk data export activity in WooCommerce order logs or admin audit logs not associated with a known admin user session.

Mitigation and workarounds

Site administrators should update the ReviewX plugin to a version beyond 2.2.12 as soon as a patched release is available from the plugin vendor. In the interim, disabling the ReviewX plugin entirely is the most effective workaround to eliminate the attack surface. Additionally, deploying a Web Application Firewall (WAF) rule to block unauthenticated access to ReviewX REST API endpoints can provide temporary protection. Monitor the official WordPress plugin repository and Wordfence advisories for patch availability (Wordfence).

Community reactions

The vulnerability was reported and assigned by Wordfence, a leading WordPress security firm, and has been indexed by ENISA's European Vulnerability Database (EUVD). Coverage has been limited to automated vulnerability tracking platforms and security aggregators at this time, with no notable researcher commentary or significant social media discussion observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management