CVE-2026-94274: YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API
The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YayReviews WordPress pluginto a version that resolves this vulnerability.Fixed in 1.4.1
Event History
Frequently Asked Questions
Which installations are affected?
YayReviews versions 1.0.4 through 1.4.0 are affected. Version 1.4.1 is identified as the version where access to the exposed API route is restricted.
Does an attacker need an account or other authentication?
No. The API route can be accessed by unauthenticated attackers, so an attacker does not need a WordPress account to harvest exposed review records.
What information can be exposed?
The route returns individual customer review records, including reviewer email addresses, other non-public review content, and reviews that are still pending moderation.