Review Manager
Review Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Review Manager has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by LVT-tholv2k. Review Manager is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-31836Review Manager <= 2.2.0 - Missing Authorization
Read the full analysisVulnerability Records

Review Manager
Author
matthewrubin
The Review Manager® WordPress plugin extends the functionality of the SaaS Review Manager® to WordPress so that the review feed can be displayed on the WordPress website. The plugin is for customers of Review Manager® that have an active subscription with the company. More information Please visit the plugin website at https://www.mrmarketingres.com/review-manager/ for more information. Supporting future development Request Reviews via email and SMS Track your online reviews Publish your online reviews to your website with our WordPress plugin and website review widget
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C