The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.
CVE-2026-94274
NONE
Updated Sep 30, 2026
WordPress
CVE Details
CVE ID
CVE-2026-94274
Published Date
Sep 30, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory