Vulnerabilities > Wpdeveloper > Reviewx > 1.6.12

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-43323 Unspecified vulnerability in Wpdeveloper Reviewx
Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.
network
low complexity
wpdeveloper
critical
9.8
2024-03-27 CVE-2024-29812 Unspecified vulnerability in Wpdeveloper Reviewx
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReviewX allows Stored XSS.This issue affects ReviewX: from n/a through 1.6.22.
network
low complexity
wpdeveloper
5.4
2023-06-06 CVE-2023-2833 Improper Privilege Management vulnerability in Wpdeveloper Reviewx
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function.
network
low complexity
wpdeveloper CWE-269
8.8