CVE-2025-10736Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up to, and including, 2.2.10. This makes it possible for unauthenticated attackers to access protected REST API endpoints, extract and modify information related to users and plugin's configuration

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-23); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-23: 1Mentions · 2026-03-24: 103-2303-24
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-231
Disclosure1
2026-03-241
General1
Full discourse2 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2025-10736 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-10736 #CVE-2025-10736 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/MF6HRPs6i6

    Post summary

    The tweet announces CVE-2025‑10736 with a medium severity rating for Wordpress and provides a link to the NVD entry, but it lacks concrete technical details or exploit information.

    00000152
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-10736 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized acces… https://www.cve.org/CVERecord?id=CVE-2025-10736

    Post summary

    The snippet announces CVE-2025-10736, noting that the ReviewX WordPress plugin is vulnerable to unauthorized access, with a link to the official CVE record.

    0000077
    56.8K followersView on X

Explore more