Description
Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the vulnerability is an unauthenticated Cross‑Site Scripting flaw (CWE‑79) in the WordPress ReviewX plugin for versions up to 2.3.10, permitting attacker‑controlled data to be rendered as part of the HTML output and enabling arbitrary client‑side scripts to execute.

Affected Systems

Any WordPress site that has installed the ReviewX plugin at or below version 2.3.10 is vulnerable. Sites running version 2.3.11 or newer have the available patch and are not affected.

Risk and Exploitability

The CVSS score of 7.1 classifies this flaw as high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits have been reported. Based on the description, the likely attack vector is any unauthenticated user who can access the vulnerable pages and inject malicious scripts by supplying crafted input through the plugin’s interfaces. While the expected exploitation probability is low, the high severity indicates that successful exploitation could lead to client‑side script execution in the context of the site’s front end.

Generated by OpenCVE AI on July 21, 2026 at 11:49 UTC.

Remediation

Vendor Solution

Update the WordPress ReviewX Plugin to the latest available version (at least 2.3.11).


OpenCVE Recommended Actions

  • Update the ReviewX plugin to version 2.3.11 or newer.
  • Ensure that all data handled by the plugin is properly sanitized and escaped before being output, following best practices for CWE‑79.
  • Deploy a content‑security‑policy that restricts or filters malicious scripts served by the ReviewX plugin.

Generated by OpenCVE AI on July 21, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Reviewx
Reviewx reviewx
Wordpress
Wordpress wordpress
Vendors & Products Reviewx
Reviewx reviewx
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.
Title WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Reviewx Reviewx
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:42:52.044Z

Reserved: 2026-06-24T12:45:36.889Z

Link: CVE-2026-57359

cve-icon Vulnrichment

Updated: 2026-07-02T12:42:48.575Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')