| CVE-2024-3869 | Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Coupon Search | ivole | Customer Reviews for WooCommerce | Medium | 4.3 | 2024-04-16 12:51:46 | Deep Dive |
| CVE-2024-1849 | WP Customer Reviews < 3.7.1 - Malicious Redirect via HTTP-EQUIV Injection | Unknown | WP Customer Reviews | - | - | 2024-04-15 05:00:05 | Deep Dive |
| CVE-2023-48275 | WordPress Widgets for Google Reviews plugin <= 11.0.2 - Arbitrary File Upload vulnerability | Trustindex.io | Widgets for Google Reviews | High | 8.0 | 2024-03-26 20:45:46 | Deep Dive |
| CVE-2024-2080 | LiquidPoll – Polls, Surveys, NPS and Feedback Reviews <= 3.3.76 - Information Exposure | liquidpoll | LiquidPoll – Polls, Surveys, NPS and Feedback Reviews | Medium | 4.3 | 2024-03-22 01:59:59 | Deep Dive |
| CVE-2024-29093 | WordPress Builder for WooCommerce reviews shortcodes – ReviewShort plugin <= 1.01.3 - Cross Site Request Forgery (CSRF) vulnerability | Saleswonder Team: Tobias | Builder for WooCommerce reviews shortcodes – ReviewShort | Medium | 4.3 | 2024-03-19 16:40:14 | Deep Dive |
| CVE-2024-29095 | WordPress Site Reviews plugin <= 6.11.6 - Cross Site Scripting (XSS) vulnerability | Gemini Labs | Site Reviews | Medium | 5.9 | 2024-03-19 16:06:58 | Deep Dive |
| CVE-2024-25597 | WordPress Ultimate Reviews plugin <= 3.2.8 - Unauthenticated Cross Site Scripting (XSS) vulnerability | Etoile Web Design | Ultimate Reviews | High | 7.1 | 2024-03-15 14:01:45 | Deep Dive |
| CVE-2024-2293 | Site Reviews <= 6.11.4 - Authenticated(Subscriber+) Stored Cross-Site Scripting via display name | geminilabs | Site Reviews | Medium | 6.4 | 2024-03-13 15:27:00 | Deep Dive |
| CVE-2023-51692 | WordPress Customer Reviews for WooCommerce Plugin <= 5.38.1 is vulnerable to Broken Access Control | CusRev | Customer Reviews for WooCommerce | Medium | 4.3 | 2024-02-28 18:49:02 | Deep Dive |
| CVE-2024-1044 | Customer Reviews for WooCommerce <= 5.38.10 - Improper Authorization via submit_review | ivole | Customer Reviews for WooCommerce | Medium | 5.3 | 2024-02-20 18:56:28 | Deep Dive |
| CVE-2023-6884 | Plugin for Google Reviews <= 3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode | widgetpack | Rich Showcase for Google Reviews | Medium | 6.4 | 2024-02-05 21:21:56 | Deep Dive |
| CVE-2024-24838 | WordPress Five Star Restaurant Reviews Plugin <= 2.3.5 is vulnerable to Cross Site Scripting (XSS) | Five Star Plugins | Five Star Restaurant Reviews | Medium | 6.5 | 2024-02-05 06:35:38 | Deep Dive |
| CVE-2023-0079 | Customer Reviews for WooCommerce < 5.17.0 - Contributor+ Stored XSS | Unknown | Customer Reviews for WooCommerce | - | - | 2024-01-16 15:54:59 | Deep Dive |
| CVE-2023-6979 | Customer Reviews for WooCommerce <= 5.38.9 - Authenticated (Author+) Arbitrary File Upload | ivole | Customer Reviews for WooCommerce | High | 8.8 | 2024-01-11 08:32:34 | Deep Dive |
| CVE-2023-52213 | WordPress Rate Star Review Plugin <= 1.5.1 is vulnerable to Cross Site Scripting (XSS) | VideoWhisper | Rate Star Review – AJAX Reviews for Content, with Star Ratings | High | 7.1 | 2024-01-08 19:26:35 | Deep Dive |
| CVE-2023-52225 | WordPress Taggbox Plugin <= 3.1 is vulnerable to PHP Object Injection | Tagbox | Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics | Critical | 10.0 | 2024-01-08 17:13:22 | Deep Dive |
| CVE-2023-33214 | WordPress Taggbox Plugin <= 3.1 is vulnerable to Cross Site Request Forgery (CSRF) | Tagbox | Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics | Medium | 5.4 | 2023-12-18 15:48:15 | Deep Dive |
| CVE-2023-4686 | WP Customer Reviews <= 3.6.6 - Authenticated (Subscriber+) Sensitive Information Exposure | bompus | WP Customer Reviews | Medium | 4.3 | 2023-11-22 15:33:22 | Deep Dive |
| CVE-2023-47653 | WordPress TWB Woocommerce Reviews Plugin <= 1.7.5 is vulnerable to Cross Site Scripting (XSS) | Abu Bakar | TWB Woocommerce Reviews | Medium | 5.9 | 2023-11-14 18:53:19 | Deep Dive |
| CVE-2022-46809 | WordPress ReviewX Plugin <= 1.6.7 is vulnerable to CSV Injection | WPDeveloper | ReviewX – Multi-criteria Rating & Reviews for WooCommerce | 超危 | - | 2023-11-07 16:37:51 | Deep Dive |