Description
The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Disclosure
Action: Patch/Update
AI Analysis

Impact

The vulnerability is a CWE-200 Information Exposure and CWE-284 Improper Access Control. An unauthenticated WordPress plugin route allows anyone to query a REST API endpoint that returns individual customer review records, including those pending moderation. The data includes email addresses and other review content that are not intended for public consumption. An attacker can harvest this sensitive information, compromising user privacy and potentially enabling further targeting.

Affected Systems

WordPress sites using YayReviews plugin versions 1.0.4 through 1.4.0 are affected. The vulnerability exists in all builds prior to 1.4.1.

Risk and Exploitability

There is no EPSS score or KEV listing, but the exposure is immediate and does not require elevated privileges; any internet‑connected WordPress installation running the affected plugin can be queried by anyone. While the CVSS score is not provided, the lack of authentication protects the data from an otherwise healthy site, making the risk substantial for all users who receive or post reviews."

Generated by OpenCVE AI on September 30, 2026 at 12:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update YayReviews to version 1.4.1 or later so the API route is properly locked down.
  • If an update cannot be applied immediately, add an authentication requirement to the vulnerable REST API route or block the endpoint entirely with a firewall or WordPress security plugin.
  • Implement additional application or network‑level hardening—such as disabling unused REST API endpoints or whitelisting only trusted hosts—to reduce potential attack surface.

Generated by OpenCVE AI on September 30, 2026 at 12:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 30 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.
Title YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-30T13:37:21.390Z

Reserved: 2026-09-21T09:21:44.365Z

Link: CVE-2026-94274

cve-icon Vulnrichment

Updated: 2026-09-30T13:20:47.381Z

cve-icon NVD

Status : Received

Published: 2026-09-30T06:17:10.367

Modified: 2026-09-30T14:17:46.243

Link: CVE-2026-94274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control