CVE-2025-10731Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allReminderSettings function. This makes it possible for unauthenticated attackers to obtain authentication tokens and subsequently bypass admin restrictions to access and export sensitive data including order details, names, emails, addresses, phone numbers, and user information.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Technical Details · 2026-03-23: 203-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-10731 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-10731 #CVE-2025-10731 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/su2BTplDjl

    Post summary

    A simple CVE-2025-10731 alert for WordPress noting medium severity, with only basic severity and product info and a link to the NVD page—no exploit, patch, or PoC details.

    0001087
    111 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-10731 Unauthenticated Sensitive Information Exposure in ReviewX WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-10731

    Post summary

    The post announces CVE‑2025‑10731, a vulnerability in the ReviewX WordPress plugin that allows unauthenticated users to access sensitive information.

    0000044
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-10731 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Informat… https://www.cve.org/CVERecord?id=CVE-2025-10731

    Post summary

    The text announces the discovery of a vulnerability in the ReviewX WooCommerce plugin, without any PoC, exploit, patch, or detailed technical description.

    0000064
    56.8K followersView on X

Explore more