CVE-2025-10679Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input validation in the bulkTenReviews function that allows user-controlled data to be passed directly to a variable function call mechanism. This makes it possible for unauthenticated attackers to call arbitrary PHP class methods that take no inputs or have default values, potentially leading to information disclosure or remote code execution depending on available methods and server configuration.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-23: 203-23
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2025-10679 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-10679 #CVE-2025-10679 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/kLJEADulL9

    Post summary

    The tweet simply announces CVE‑2025‑10679 with its severity rating and affected product, without providing any additional technical details, proofs of concept, or exploitation activity.

    0000082
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-10679 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method c… https://www.cve.org/CVERecord?id=CVE-2025-10679

    Post summary

    The announcement reports that the ReviewX WordPress plugin is vulnerable to an arbitrary method, referencing the CVE record but providing no exploitation details or remediation steps.

    0000061
    56.8K followersView on X

Explore more