CVE-2025-14070: Xfinitysoft Reviewify — Review Discounts & Photo/video Reviews For Woocommerce

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'send_test_email' AJAX action in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to create arbitrary WooCommerce discount coupons, potentially causing financial loss to the store.

Affected products

  • Xfinitysoft Reviewify — Review Discounts & Photo/video Reviews For Woocommerce: up to and including 1.0.7

Published 2026-01-07. Last modified 2026-06-17.