CVE-2026-94274

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.

https://wpscan.com/vulnerability/23965307-678d-4f59-beae-5a8b33af9a75/