
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10731 is a Sensitive Information Exposure vulnerability in the ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress. It affects all versions up to and including 2.2.12, and was published on March 23, 2026, with Wordfence credited as the assigner. The flaw allows unauthenticated attackers to obtain authentication tokens via the allReminderSettings function, subsequently bypassing admin restrictions to access and export sensitive customer data. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-285 (Improper Authorization). The allReminderSettings function in the plugin's REST API does not enforce proper authentication checks, allowing unauthenticated HTTP requests to retrieve authentication tokens. These tokens can then be used to bypass the AdminMiddleware access controls and invoke privileged endpoints such as those in DataSyncController, enabling export of sensitive store data. The vulnerable code paths are visible in the plugin's source at EmailTemplateController.php, AdminMiddleware.php, and DataSyncController.php (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated remote attackers to obtain admin-level authentication tokens and access sensitive WooCommerce store data, including order details, customer names, email addresses, physical addresses, phone numbers, and user account information. The impact is primarily a confidentiality breach (no integrity or availability impact), but the exposed data could facilitate phishing campaigns, identity theft, or further targeted attacks against store customers and administrators (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.093%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and low complexity, making it straightforward to exploit if a proof-of-concept is published (Wordfence).
/wp-content/plugins/reviewx/ for plugin presence.allReminderSettings function (e.g., /wp-json/reviewx/v1/...) to retrieve an authentication token exposed in the response.AdminMiddleware, effectively impersonating an admin user.DataSyncController export endpoint with the token to download sensitive WooCommerce data including order details, customer names, emails, addresses, and phone numbers (Wordfence, WordPress Trac)./wp-json/reviewx/v1/) from unknown IP addresses, particularly those fetching reminder settings or triggering data sync/export operations.Site administrators should update the ReviewX plugin to a version beyond 2.2.12 as soon as a patched release is available from the plugin vendor. In the interim, disabling the ReviewX plugin entirely is the most effective workaround to eliminate the attack surface. Additionally, deploying a Web Application Firewall (WAF) rule to block unauthenticated access to ReviewX REST API endpoints can provide temporary protection. Monitor the official WordPress plugin repository and Wordfence advisories for patch availability (Wordfence).
The vulnerability was reported and assigned by Wordfence, a leading WordPress security firm, and has been indexed by ENISA's European Vulnerability Database (EUVD). Coverage has been limited to automated vulnerability tracking platforms and security aggregators at this time, with no notable researcher commentary or significant social media discussion observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."