Impact
The Customer Reviews for WooCommerce plugin is vulnerable to Reflected Cross‑Site Scripting through the 'crsearch' parameter. The flaw allows unauthenticated attackers to inject arbitrary JavaScript that is reflected back to a victim when they follow a crafted link, causing the script to execute in the victim's browser session. The vulnerability stems from insufficient input sanitization and output escaping.
Affected Systems
WordPress sites running the Customer Reviews for WooCommerce plugin from ivole version 5.101.0 or earlier are affected. Any installation of the plugin at or below that version on any WordPress installation constitutes a vulnerable system.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers do not need authentication and can exploit the flaw by sending an HTTP request containing a malicious 'crsearch' query, for example via a phishing link that a user clicks.
OpenCVE Enrichment