Impact
The Customer Reviews for WooCommerce plugin before version 5.118.0 accepts review comments from a publicly accessible endpoint without sanitising or escaping the input. This flaw allows an unauthenticated user to embed malicious script into stored reviews. When a site visitor later views the affected review, the browser executes the injected script, potentially compromising the visitor’s confidentiality and integrity. The vulnerability does not provide direct server‑side code execution.
Affected Systems
The vulnerability affects WordPress installations that have the Customer Reviews for WooCommerce plugin installed in a version earlier than 5.118.0 and that expose the comment submission endpoint to the public. Any site that has published reviews using the affected plugin is at risk. Administrators should confirm the plugin version and the exposure of the endpoint to determine impact.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity. An attacker only needs to send a crafted comment payload to the public endpoint; no authentication is required. The EPSS score of less than 1% suggests a low overall probability of exploitation on the public internet, but the lack of an authentication requirement means any exposed WordPress site could be targeted. The vulnerability is not currently listed in CISA’s KEV catalog, but its ability to inject code into visitors’ browsers makes it a significant concern for site administrators.
OpenCVE Enrichment