Impact
The Photo Reviews for WooCommerce plugin allows unauthenticated users to inject arbitrary JavaScript through the 'wcpr_image_upload_id' parameter. The value is stored in comment metadata without escaping, so the payload is rendered whenever a review page is viewed, enabling attackers to execute scripts in the browsers of visitors. This flaw is a Stored DOM‑Based XSS (CWE‑79) that can compromise user confidentiality and integrity by injecting malicious code into the page context.
Affected Systems
All WordPress sites that have installed the Photo Reviews for WooCommerce plugin with version 1.2.30 or earlier are affected. The vulnerability exists in the review submission handling code that embeds the 'wcpr_image_upload_id' value into the frontend without validation.
Risk and Exploitability
With a CVSS score of 7.2, the vulnerability is high severity. The EPSS score is not available, but the lack of authentication gating and the ability for any user to submit a review mean that exploitation is straightforward and likely. The issue is not listed in CISA KEV, but the nature of the attack vector—public submission and stored XSS—makes exploitation probable if the site is reachable over the web. Attacks would execute as the victim user when the compromised review page is loaded.
OpenCVE Enrichment