Known Vulnerabilities for Reviews Plus by Implecode
Listed below are 1 of the newest known vulnerabilities associated with "Reviews Plus" by "Implecode".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103340 json | Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access ... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-102362 json | mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthe... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-101923 json | The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and inc... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-101162 json | The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting t... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-101160 json | The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before stori... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-101159 json | The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its publ... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-100517 json | Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-100515 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Review... | Not Provided | 2026-10-05 | 2026-10-06 |
| CVE-2026-100148 json | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reviews[].tex... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-97663 json | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Nam... | Not Provided | 2026-10-02 | 2026-10-02 |