🔐 CVE Alert

CVE-2026-94274

UNKNOWN 0.0

YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.

Vendor unknown
Product yayreviews
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown yayreviews

Be the first to know when new unknown vulnerabilities affecting unknown yayreviews are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / YayReviews
1.0.4 < 1.4.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/23965307-678d-4f59-beae-5a8b33af9a75/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan