Impact
The Customer Reviews for WooCommerce plugin before version 5.118.0 fails to sanitize and escape content submitted through its comment endpoint, allowing an unauthenticated user to inject malicious script into stored reviews. This flaw enables Stored Cross‑Site Scripting, which can compromise the security state of any visitor who views the affected review display, potentially allowing attackers to steal session cookies, deface pages, or hijack user sessions. The vulnerability relies on client‑side execution of code in the context of the victim’s browser and does not grant remote code execution on the server itself.
Affected Systems
The affected systems are WordPress sites running the Customer Reviews for WooCommerce plugin with any version earlier than 5.118.0. Sites that have left the plugin installed and have not applied the patch are at risk. Vendors or developers who rely on this plugin should examine their WordPress installations to confirm whether the vulnerable plugin is present and whether any users are publishing reviews.
Risk and Exploitability
The exploit is simple to craft, as it only requires sending a crafted comment payload to the plugin’s endpoint without authentication. While no EPSS score is available, the lack of an authentication requirement indicates a high likelihood of exploitation in environments with exposed WordPress installations. The vulnerability is not currently listed in CISA’s KEV catalog, but its impact on confidentiality and integrity of all site visitors makes it a critical concern for site administrators.
OpenCVE Enrichment