Impact
WP Customer Reviews plugins up to version 3.7.5 improperly process the 'wpcr3_fname' input, resulting in reflected cross‑site scripting that can execute arbitrary scripts when a victim follows a crafted link. The flaw allows unauthenticated attackers to inject malicious code that runs in the victim’s browser, potentially compromising user credentials, defacing sites, or stealing information. The weakness is identified as CWE-79.
Affected Systems
WordPress sites running the WP Customer Reviews plugin version 3.7.5 or earlier. The plugin is distributed by bompus under the WP Customer Reviews name.
Risk and Exploitability
The CVSS score is 7.2, indicating moderate‑to‑high impact, while the EPSS score is below 1%, suggesting low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers typically exploit the flaw by embedding malicious content into the wpcr3_fname parameter via a link. Victims require no authentication to trigger the script, making social engineering feasible. Disabling the vulnerable parameter or updating the plugin are the primary mitigation routes.
OpenCVE Enrichment