Impact
The Customer Reviews for WooCommerce plugin fails to sanitize or escape the value supplied to the ‘color’ shortcode attribute, allowing an authenticated contributor or higher to embed arbitrary JavaScript into the review content. When that content is viewed by a visitor, the script executes with the visitor’s privileges, potentially stealing session cookies, modifying page content, or facilitating further attacks targeting the user. This vulnerability is a stored cross‑site scripting flaw, classified as CWE‑79, and does not provide direct remote code execution on the server.
Affected Systems
All ivole Customer Reviews for WooCommerce installations up to and including version 5.113.0. Any WordPress site that incorporates any of these plugin releases is eligible for exploitation when an attacker has at least contributor‑level access.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. The EPSS score is below 1 %, suggesting a low likelihood of current exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated attacker with contributor or higher permissions; from that position the attacker can submit a review containing malicious payloads that are persisted and later executed for all site visitors. Based on the description, it inferred that the attack vector would involve the WordPress administrative interface, where the attacker inputs the malicious ‘color’ attribute value into a review widget.
OpenCVE Enrichment