Description
The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Published: 2026-09-19
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting via the wpcr3_fname query parameter
Action: Patch
AI Analysis

Impact

The plugin fails to sanitize or escape the wpcr3_fname parameter, allowing an attacker to embed arbitrary JavaScript that will be reflected in the server response. This is a classic reflected XSS flaw identified as CWE‑79. An unauthenticated actor can craft a link targeting the vulnerable parameter and, if a user follows it, the malicious script will execute in that user’s browser, potentially leading to theft of session cookies, defacement, or drive‑by malware execution.

Affected Systems

WordPress sites running the WP Customer Reviews plugin version 3.7.8 or earlier, as distributed by bompus. The vulnerability exists in all releases up to and including 3.7.8.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability that existing exploit code is being actively used. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit the flaw via a crafted URL or embedded link, exploiting phishing or other social‑engineering avenues.

Generated by OpenCVE AI on September 19, 2026 at 23:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Customer Reviews to version 3.7.9 or later
  • If an upgrade is not immediately possible, remove or disable the wpcr3_fname query parameter by adjusting the plugin’s configuration or filtering the request with a custom hook
  • Implement an application‑level input filter or content security policy to block the execution of unexpected scripts

Generated by OpenCVE AI on September 19, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Bompus
Bompus wp Customer Reviews
Wordpress
Wordpress wordpress
Vendors & Products Bompus
Bompus wp Customer Reviews
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title WP Customer Reviews <= 3.7.8 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Bompus Wp Customer Reviews
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:25.278Z

Reserved: 2026-06-08T15:56:56.336Z

Link: CVE-2026-11608

cve-icon Vulnrichment

Updated: 2026-09-19T13:55:35.792Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:50.633

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-11608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')