ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Security & Risk Analysis

wordpress.org/plugins/reviewx

Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.

9K active installs v2.3.6 PHP 7.4+ WP 5.0+ Updated Mar 15, 2026
customer-reviewsgoogle-reviewsproduct-reviewsreview-reminderwoocommerce-reviews
93
A · Safe
CVEs total9
Unpatched0
Last CVEAug 16, 2024
Safety Verdict

Is ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Safe to Use in 2026?

Generally Safe

Score 93/100

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema has a strong security track record. Known vulnerabilities have been patched promptly.

9 known CVEsLast CVE: Aug 16, 2024Updated 19d ago
Risk Assessment

The reviewx plugin v2.3.6 presents a mixed security posture. While the static analysis shows a clean slate regarding immediate exploitable entry points like AJAX handlers, REST API routes, and shortcodes without proper authorization checks, and no critical or high severity taint flows were detected, there are significant underlying concerns. The plugin has a history of 9 CVEs, with 3 high and 6 medium severity vulnerabilities, indicating a pattern of recurring security flaws such as improper input validation, missing authorization, and cross-site scripting. This historical context is concerning, especially given the recent vulnerability discovered on August 16, 2024.

The static analysis also reveals some weaknesses. Only 4% of output escaping is properly implemented, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities, even if not flagged by the taint analysis in this specific version. The fact that 19% of SQL queries are not using prepared statements also points to a potential for SQL injection vulnerabilities. The bundling of Guzzle, a common library, might introduce risks if it's an outdated or vulnerable version, though the analysis doesn't specify this.

Overall, while the current version appears to have closed known vulnerabilities and lacks immediate critical entry points, the historical pattern of numerous high and medium severity issues, coupled with poor output escaping and a percentage of raw SQL queries, suggests a plugin that requires vigilance. Users should be aware of the plugin's past security record and monitor for future updates and potential discoveries.

Key Concerns

  • High percentage of improperly escaped output
  • Significant number of non-prepared SQL queries
  • History of 3 high severity CVEs
  • History of 6 medium severity CVEs
  • Bundled library (Guzzle)
Vulnerabilities
9

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
4 CVEs in 2023
2023
4 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

High
3
Medium
6

9 total CVEs

CVE-2024-43323medium · 5.3Improper Input Validation

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.28 - Insufficient Input Validation

Aug 16, 2024 Patched in 1.6.29 (4d)
CVE-2024-3609medium · 4.3Missing Authorization

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization

May 16, 2024 Patched in 1.6.28 (1d)
CVE-2024-33921medium · 4.3Missing Authorization

ReviewX <= 1.6.21 - Missing Authorization

Apr 29, 2024 Patched in 1.6.22 (9d)
CVE-2024-29812medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ReviewX <= 1.6.22 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 25, 2024 Patched in 1.6.23 (8d)
CVE-2023-40670medium · 4.3Missing Authorization

ReviewX <= 1.6.17 - Missing Authorization in rx_coupon_from_submit

Aug 22, 2023 Patched in 1.6.18 (154d)
CVE-2023-2833high · 8.8Improper Privilege Management

ReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation

May 31, 2023 Patched in 1.6.14 (237d)
CVE-2023-26325high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.8 - Authenticated (Subscriber+) SQL Injection

Apr 19, 2023 Patched in 1.6.9 (279d)
CVE-2022-46809medium · 6.5Improper Neutralization of Formula Elements in a CSV File

ReviewX <= 1.6.7 - Unauthenticated CSV Injection

Apr 13, 2023 Patched in 1.6.8 (285d)
WF-6c3032ae-eb86-47d0-b160-320a67a380e1-reviewxhigh · 8.3Cross-Site Request Forgery (CSRF)

WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX < 1.2.9 - Cross-Site Request Forgery

Jun 30, 2021 Patched in 1.2.9 (937d)
Code Analysis
Analyzed Mar 16, 2026

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
39 prepared
Unescaped Output
119
5 escaped
Nonce Checks
7
Capability Checks
4
File Operations
4
External Requests
3
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

81% prepared48 total queries

Output Escaping

4% escaped124 total outputs
Attack Surface

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Attack Surface

Entry Points0
Unprotected0

Scheduled Events 2

category_sync_event
process_order_update
Maintenance & Trust

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads609K

Community Trust

Rating90/100
Number of ratings84
Active installs9K
Developer Profile

ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Developer Profile

ReviewX

1 plugin · 9K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
213 days
View full developer profile
Detection Fingerprints

How We Detect ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reviewx/app/Customize/assets/js/reviewx-customize.js
Script Paths
/wp-content/plugins/reviewx/app/Customize/assets/js/reviewx-customize.js
Version Parameters
reviewx-customize?ver=

HTML / DOM Fingerprints

CSS Classes
rvx_form_inputrvx_reviews_overview_sectionrvx_filter_sectionrvx_review_items_sectionrvx_form_section
HTML Comments
ReviewX Customize options - live preview jsReviewX Customize options DataAdd Section to the Panel [ReviewX -> Reviews Overview Section]ReviewX - General Settings+8 more
Data Attributes
data-customize-setting-link="rvx_reviews_overview_rating_out_of_text_color"data-customize-setting-link="rvx_reviews_overview_rating_out_of_text_font_size"data-customize-setting-link="rvx_reviews_overview_rating_out_of_total_text_color"data-customize-setting-link="rvx_reviews_overview_rating_out_of_total_text_font_size"data-customize-setting-link="rvx_reviews_overview_rating_badge_background_color"data-customize-setting-link="rvx_reviews_overview_rating_badge_text_color"
JS Globals
REVIEWX_VERSIONREVIEWX_CUSTOMIZER_URL
FAQ

Frequently Asked Questions about ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema