CVE-2026-94274
YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.
| Vendor | unknown |
| Product | yayreviews |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown yayreviews
Be the first to know when new unknown vulnerabilities affecting unknown yayreviews are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / YayReviews
1.0.4 < 1.4.1
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan