The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber access and above, to delete attachments.
History

Fri, 27 Jun 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpdeveloper
Wpdeveloper reviewx
Weaknesses CWE-862
CPEs cpe:2.3:a:wpdeveloper:reviewx:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpdeveloper
Wpdeveloper reviewx

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-05-16T20:31:04.842Z

Updated: 2024-08-01T20:19:58.893Z

Reserved: 2024-04-10T17:31:53.592Z

Link: CVE-2024-3609

cve-icon Vulnrichment

Updated: 2024-08-01T20:19:58.893Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-16T21:16:10.443

Modified: 2025-06-27T18:08:33.780

Link: CVE-2024-3609

cve-icon Redhat

No data.