Impact
The plugin fails to sanitize or escape the wpcr3_fname parameter, allowing an attacker to embed arbitrary JavaScript that will be reflected in the server response. This is a classic reflected XSS flaw identified as CWE‑79. An unauthenticated actor can craft a link targeting the vulnerable parameter and, if a user follows it, the malicious script will execute in that user’s browser, potentially leading to theft of session cookies, defacement, or drive‑by malware execution.
Affected Systems
WordPress sites running the WP Customer Reviews plugin version 3.7.8 or earlier, as distributed by bompus. The vulnerability exists in all releases up to and including 3.7.8.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability that existing exploit code is being actively used. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit the flaw via a crafted URL or embedded link, exploiting phishing or other social‑engineering avenues.
OpenCVE Enrichment