Description
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The publicly-emitted `wcpr_image_upload` nonce printed on every product review form is the only gate, and no capability, authentication, or attachment ownership check is performed, allowing the payload to be stored in comment meta — which is not subject to `wp_kses` — by any unauthenticated visitor; the XSS fires once the review is visible on the frontend.
Published: 2026-10-10
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored DOM-Based Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The Photo Reviews for WooCommerce plugin allows unauthenticated users to inject arbitrary JavaScript through the 'wcpr_image_upload_id' parameter. The value is stored in comment metadata without escaping, so the payload is rendered whenever a review page is viewed, enabling attackers to execute scripts in the browsers of visitors. This flaw is a Stored DOM‑Based XSS (CWE‑79) that can compromise user confidentiality and integrity by injecting malicious code into the page context.

Affected Systems

All WordPress sites that have installed the Photo Reviews for WooCommerce plugin with version 1.2.30 or earlier are affected. The vulnerability exists in the review submission handling code that embeds the 'wcpr_image_upload_id' value into the frontend without validation.

Risk and Exploitability

With a CVSS score of 7.2, the vulnerability is high severity. The EPSS score is not available, but the lack of authentication gating and the ability for any user to submit a review mean that exploitation is straightforward and likely. The issue is not listed in CISA KEV, but the nature of the attack vector—public submission and stored XSS—makes exploitation probable if the site is reachable over the web. Attacks would execute as the victim user when the compromised review page is loaded.

Generated by OpenCVE AI on October 10, 2026 at 08:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Photo Reviews for WooCommerce plugin to a version newer than 1.2.30.
  • If an upgrade is not feasible, edit or disable the code that accepts the 'wcpr_image_upload_id' parameter so that unauthenticated submissions cannot store arbitrary JavaScript, or add sanitization to comment meta handling.
  • Deploy a Content Security Policy that limits script execution on pages containing reviews, reducing the impact of any stored XSS payloads.

Generated by OpenCVE AI on October 10, 2026 at 08:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The publicly-emitted `wcpr_image_upload` nonce printed on every product review form is the only gate, and no capability, authentication, or attachment ownership check is performed, allowing the payload to be stored in comment meta — which is not subject to `wp_kses` — by any unauthenticated visitor; the XSS fires once the review is visible on the frontend.
Title Photo Reviews for WooCommerce <= 1.2.30 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'wcpr_image_upload_id' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:12.618Z

Reserved: 2026-09-25T12:19:45.294Z

Link: CVE-2026-100161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:38.767

Modified: 2026-10-10T07:16:38.767

Link: CVE-2026-100161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')