Known Vulnerabilities for Reviews Plus by Implecode
Listed below are 1 of the newest known vulnerabilities associated with "Reviews Plus" by "Implecode".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86784 json | The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before ou... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-86111 json | BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated atta... | Not Provided | 2026-09-05 | 2026-09-08 |
| CVE-2026-85678 json | The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it insi... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-85677 json | The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements t... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-84927 json | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews ... | Not Provided | 2026-09-05 | 2026-09-06 |
| CVE-2026-84926 json | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to ... | Not Provided | 2026-09-05 | 2026-09-06 |
| CVE-2026-84899 json | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it insid... | Not Provided | 2026-09-05 | 2026-09-06 |
| CVE-2026-82925 json | The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key pro... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-81800 json | Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | Not Provided | 2026-09-10 | 2026-09-11 |
| CVE-2026-76585 json | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer rev... | Not Provided | 2026-08-30 | 2026-08-31 |