Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.3.13.
Published: 2025-09-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page rendering that allows an attacker to inject arbitrary JavaScript into pages generated by the WooCommerce Photo Reviews plugin. Based on the description, it is inferred that attackers can perform this injection by accessing affected pages, which can lead to defacement, cookie theft, phishing, or other malicious actions executed in the context of legitimate users. The weakness is a classic input validation flaw categorized as CWE‑79.

Affected Systems

WordPress sites using the WooCommerce Photo Reviews plugin from villatheme, versions up to and including 1.3.13, are affected. Users should verify their plugin version and upgrade if it falls within this range.

Risk and Exploitability

The CVSS score of 7.1 signifies a moderate severity flaw. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could exploit this remotely by visiting a page that renders untrusted data from the plugin, with no local privileges required. Proper input sanitization and validation are the core preventive measures according to the identified CWE.

Generated by OpenCVE AI on April 30, 2026 at 15:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WooCommerce Photo Reviews to a version newer than 1.3.13.
  • Apply any vendor-provided security patches or templates to ensure user‑supplied data is properly escaped before rendering.
  • If the plugin is not essential, disable or remove it until the fix is applied.

Generated by OpenCVE AI on April 30, 2026 at 15:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27440 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews. This issue affects WooCommerce Photo Reviews: from n/a through 1.3.13.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews. This issue affects WooCommerce Photo Reviews: from n/a through 1.3.13. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.3.13.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Villatheme
Villatheme woocommerce Photo Reviews
Wordpress
Wordpress wordpress
Vendors & Products Villatheme
Villatheme woocommerce Photo Reviews
Wordpress
Wordpress wordpress

Tue, 09 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews. This issue affects WooCommerce Photo Reviews: from n/a through 1.3.13.
Title WordPress WooCommerce Photo Reviews plugin <= 1.3.13 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Villatheme Woocommerce Photo Reviews
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:45.420Z

Reserved: 2025-05-07T09:55:20.908Z

Link: CVE-2025-47570

cve-icon Vulnrichment

Updated: 2025-09-09T17:50:13.851Z

cve-icon NVD

Status : Deferred

Published: 2025-09-09T17:15:46.280

Modified: 2026-04-23T15:30:30.437

Link: CVE-2025-47570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:30:16Z

Weaknesses