Impact
The Photo Reviews for WooCommerce plugin, versions up to 1.2.30, contains a Missing Authorization flaw (CWE‑862). When an unauthenticated user submits a review, the plugin stores values from the wcpr_image_upload_id parameter as comment meta without checking attachment ownership. Later, the delete_reviews_image() routine calls wp_delete_post( $id, true ) for every stored ID when a review is deleted, giving the attacker the ability to permanently delete any post, page, media attachment, or other WordPress content.
Affected Systems
Affected products include the villatheme Photo Reviews for WooCommerce plugin for WordPress. All versions dated 1.2.30 or earlier are vulnerable. No other vendors or versions are listed.
Risk and Exploitability
The vulnerability scores a CVSS 8.1, indicating a high severity with full impact on confidentiality, integrity, and availability of site content. EPSS is not available, and the flaw is not yet in any KEV catalog. Because the flaw is triggered via a publicly accessible review submission endpoint, an attacker can exploit it remotely without authentication. Based on the description, it is inferred that the likely attack vector is an unauthenticated user submitting a review with malicious wcpr_image_upload_id values via the public endpoint, which subsequently triggers arbitrary content deletion when the review is later removed. By planting malicious wcpr_image_upload_id values in a review, the attacker forces any subsequent review deletion or automatic WordPress trash cleanup the risk substantial until patched.
OpenCVE Enrichment