Loading market data...
← Back to CVE feed

CVE-2026-94274

MEDIUM CVSS 5.3 View on NVD ↗

Description

The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Sep 30, 2026 06:17 UTC Modified: Sep 30, 2026 16:28 UTC