Unrated severityNVD Advisory· Published Sep 30, 2026
CVE-2026-94274
CVE-2026-94274
Description
The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.4.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.