Description
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker's review (or when WordPress's built-in wp_scheduled_delete cron empties the comment trash after 30 days).
Published: 2026-10-03
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted deletion of arbitrary WordPress content by unauthenticated users
Action: Immediate Patch
AI Analysis

Impact

The Photo Reviews for WooCommerce plugin, versions up to 1.2.30, contains a Missing Authorization flaw (CWE‑862). When an unauthenticated user submits a review, the plugin stores values from the wcpr_image_upload_id parameter as comment meta without checking attachment ownership. Later, the delete_reviews_image() routine calls wp_delete_post( $id, true ) for every stored ID when a review is deleted, giving the attacker the ability to permanently delete any post, page, media attachment, or other WordPress content.

Affected Systems

Affected products include the villatheme Photo Reviews for WooCommerce plugin for WordPress. All versions dated 1.2.30 or earlier are vulnerable. No other vendors or versions are listed.

Risk and Exploitability

The vulnerability scores a CVSS 8.1, indicating a high severity with full impact on confidentiality, integrity, and availability of site content. EPSS is not available, and the flaw is not yet in any KEV catalog. Because the flaw is triggered via a publicly accessible review submission endpoint, an attacker can exploit it remotely without authentication. Based on the description, it is inferred that the likely attack vector is an unauthenticated user submitting a review with malicious wcpr_image_upload_id values via the public endpoint, which subsequently triggers arbitrary content deletion when the review is later removed. By planting malicious wcpr_image_upload_id values in a review, the attacker forces any subsequent review deletion or automatic WordPress trash cleanup the risk substantial until patched.

Generated by OpenCVE AI on October 3, 2026 at 07:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Photo Reviews for WooCommerce.
  • If a patch cannot be applied immediately, temporarily disable the review submission functionality or delete all pending reviews that have not yet been processed, to stop malicious wcpr_image_upload_id values from influencing future deletions.
  • As a long‑term safeguard, ensure that any code paths that delete attachments verify the user’s ownership of the attachment before calling wp_delete_post(), aligning with best practices for authorization checks (CWE‑862).

Generated by OpenCVE AI on October 3, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker's review (or when WordPress's built-in wp_scheduled_delete cron empties the comment trash after 30 days).
Title Photo Reviews for WooCommerce <= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:44.206Z

Reserved: 2026-09-28T16:03:08.119Z

Link: CVE-2026-101923

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:14.495Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:39.603

Modified: 2026-10-03T16:16:32.120

Link: CVE-2026-101923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T07:30:20Z

Weaknesses