CVE-2026-94274 PUBLISHED

YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API

Assigner: WPScan
Reserved: 21.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.

Product Status

Vendor Unknown
Product YayReviews
Versions Default: unaffected
  • affected from 1.0.4 to 1.4.1 (excl.)

Credits

  • Pablo González Pérez finder
  • Francisco José Ramírez Vicente finder
  • and Iñigo Sánchez Enciso finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE