📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global ransomware Multiple sectors CRITICAL 26m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 2h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h Global ransomware Multiple sectors CRITICAL 26m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 2h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h Global ransomware Multiple sectors CRITICAL 26m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 2h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h
Vulnerabilities

CVE-2025-10736

Medium
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authoriz
CWE-285 — Weakness Type
Published: Mar 23, 2026  ·  Modified: Mar 24, 2026  ·  Source: NVD
CVSS v3
6.5
🔗 NVD Official
📄 Description (English)

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility() function in all versions up to, and including, 2.2.10. This makes it possible for unauthenticated attackers to access protected REST API endpoints, extract and modify information related to users and plugin's configuration

🤖 AI Executive Summary

CVE-2025-10736 affects the ReviewX WordPress plugin, allowing unauthenticated attackers to access protected REST API endpoints through improper authorization checks. Attackers can extract and modify sensitive user data and plugin configuration without authentication. With no patch currently available and the vulnerability affecting all versions up to 2.2.10, this poses an immediate risk to e-commerce platforms using this plugin across Saudi Arabia.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 11, 2026 01:01
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi e-commerce businesses, particularly those in the retail and online marketplace sectors that rely on WooCommerce for product reviews and ratings. Banking and fintech sectors using WooCommerce for payment processing are at elevated risk due to potential exposure of customer financial data. Government e-commerce initiatives and ARAMCO's digital commerce platforms could be affected. Telecommunications companies offering online services through WooCommerce are also vulnerable. The exposure of user data and configuration information could lead to compliance violations with SAMA's cybersecurity framework and NCA's essential cybersecurity controls.
🏢 Affected Saudi Sectors
E-commerce & Retail Banking & Financial Services Government & Public Sector Energy (ARAMCO digital services) Telecommunications Healthcare (online services) Hospitality & Tourism
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Audit all WooCommerce installations using ReviewX plugin versions up to 2.2.10 across your organization
2. Disable the ReviewX plugin immediately if not critical to operations, or restrict REST API access at the web application firewall level
3. Review access logs for suspicious REST API calls to endpoints: /wp-json/reviewx/* and /wp-json/*/reviewx/*
4. Conduct forensic analysis to identify if unauthorized data extraction or modification occurred

COMPENSATING CONTROLS:
5. Implement Web Application Firewall (WAF) rules to block unauthenticated access to ReviewX REST API endpoints
6. Apply IP whitelisting to REST API endpoints if possible
7. Implement rate limiting on REST API calls
8. Enable WordPress security plugins with REST API monitoring capabilities
9. Enforce strong authentication mechanisms at the application level

DETECTION RULES:
10. Monitor for POST/GET requests to /wp-json/reviewx/* without valid authentication tokens
11. Alert on unusual data extraction patterns from user endpoints
12. Track configuration modification attempts via REST API
13. Monitor for multiple failed authentication attempts followed by successful unauthenticated API calls

PATCHING:
14. Monitor ReviewX plugin repository for security updates
15. Plan immediate upgrade to patched version once available
16. Consider alternative review plugins with better security posture as interim solution
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع تثبيتات WooCommerce التي تستخدم مكون ReviewX بإصدارات حتى 2.2.10 عبر مؤسستك
2. تعطيل مكون ReviewX فوراً إذا لم يكن حرجاً للعمليات، أو تقييد وصول REST API على مستوى جدار الحماية
3. مراجعة سجلات الوصول للاتصالات المريبة بنقاط نهاية REST API: /wp-json/reviewx/* و /wp-json/*/reviewx/*
4. إجراء تحليل جنائي للتحقق من استخراج أو تعديل البيانات غير المصرح به

الضوابط التعويضية:
5. تنفيذ قواعد جدار حماية تطبيقات الويب لحظر الوصول غير المصرح به إلى نقاط نهاية ReviewX REST API
6. تطبيق القائمة البيضاء للعناوين على نقاط نهاية REST API إن أمكن
7. تنفيذ تحديد معدل على استدعاءات REST API
8. تفعيل مكونات أمان ووردبريس مع قدرات مراقبة REST API
9. فرض آليات مصادقة قوية على مستوى التطبيق

قواعد الكشف:
10. مراقبة طلبات POST/GET إلى /wp-json/reviewx/* بدون رموز مصادقة صحيحة
11. التنبيه على أنماط استخراج البيانات غير العادية من نقاط نهاية المستخدم
12. تتبع محاولات تعديل الإعدادات عبر REST API
13. مراقبة محاولات المصادقة الفاشلة المتعددة متبوعة بنجاح استدعاءات API غير المصرح بها

التصحيح:
14. مراقبة مستودع مكون ReviewX للتحديثات الأمنية
15. التخطيط للترقية الفورية إلى الإصدار المصحح بمجرد توفره
16. النظر في مكونات المراجعة البديلة ذات موقف الأمان الأفضل كحل مؤقت
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 - 5.1: Access Control - Improper authorization checks violate access control requirements ECC 2024 - 5.2: Authentication - Unauthenticated access to protected endpoints violates authentication controls ECC 2024 - 6.1: Data Protection - Unauthorized access to user data violates data protection requirements ECC 2024 - 7.1: Monitoring and Logging - Lack of proper API endpoint protection monitoring
🔵 SAMA CSF
Governance & Risk Management - Risk assessment and management of third-party plugin vulnerabilities Information Security - Access control and authentication mechanisms for sensitive data Information Security - Data protection and confidentiality of customer information Operational Resilience - Detection and response to unauthorized access attempts
🟡 ISO 27001:2022
A.5.2: User access management - Improper authorization checks A.5.3: Access rights - Unauthenticated access to protected resources A.6.1: Information security policies - Inadequate API security controls A.8.1: Asset management - Unprotected REST API endpoints A.9.1: Access control - Lack of proper authentication mechanisms A.12.4: Logging - Insufficient monitoring of API access
🟣 PCI DSS v4.0.1
Requirement 1.1: Firewall configuration standards - WAF rules needed for API protection Requirement 6.5.10: Broken access control - Direct object references in REST API Requirement 7.1: Access control - Principle of least privilege not enforced Requirement 10.2: Logging and monitoring - API access logging required
📊 CVSS Score
6.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.5
CWECWE-285
Exploit No
Patch ✗ No
Published 2026-03-23
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-285
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.