Impact
The Customer Reviews for WooCommerce plugin has a stored cross‑site scripting flaw that allows unauthenticated attackers to inject arbitrary scripts into pages that are viewed by any user. The vulnerability arises because user input in the Comment Author Name field is not properly sanitized or escaped, and it can be stored in the database and executed when the review is displayed. This flaw is a typical output‑encoding problem classified as CWE‑79.
Affected Systems
Any WordPress site running the Customer Reviews for WooCommerce plugin version 5.122.0 or earlier is affected. The flaw exists in all releases up to and including 5.122.0, regardless of other plugin or WordPress versions.
Risk and Exploitability
The vulnerability has a CVSS base score of 7.2, indicating a high risk when the conditions are met. Although EPSS data is not available, the flaw is exploitable by unauthenticated users who can submit a review with a malicious author name. Attackers must have the image attachment option (ivole_attach_image) enabled to upload a maliciously named image via the public wp_ajax_nopriv_cr_upload_local_images_frontend endpoint. The flaw is not listed in the CISA KEV catalog, but it can be leveraged remotely without authentication, which makes it a serious threat for any exposed WordPress site with the plugin enabled.
OpenCVE Enrichment