CVE-2025-10731: ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure to Data Export
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes it possible for unauthenticated attackers to obtain authentication tokens and subsequently bypass admin restrictions to access and export sensitive data including order details, names, emails, addresses, phone numbers, and user information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10731?
The severity of CVE-2025-10731 is considered to be critical due to the potential for unauthenticated sensitive information exposure.
How do I fix CVE-2025-10731?
To fix CVE-2025-10731, upgrade the ReviewX plugin to version 2.2.13 or later.
What type of attack does CVE-2025-10731 facilitate?
CVE-2025-10731 facilitates an unauthenticated sensitive information exposure vulnerability that allows attackers to export sensitive data.
Which versions of the ReviewX plugin are affected by CVE-2025-10731?
ReviewX plugin versions up to and including 2.2.12 are affected by CVE-2025-10731.
Is user authentication required to exploit CVE-2025-10731?
No, user authentication is not required to exploit CVE-2025-10731, making it easier for attackers to gain unauthorized access.