Description
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Stored Cross‑Site Scripting through Comment Author Name
Action: Apply Patch
AI Analysis

Impact

The Customer Reviews for WooCommerce plugin has a stored cross‑site scripting flaw that allows unauthenticated attackers to inject arbitrary scripts into pages that are viewed by any user. The vulnerability arises because user input in the Comment Author Name field is not properly sanitized or escaped, and it can be stored in the database and executed when the review is displayed. This flaw is a typical output‑encoding problem classified as CWE‑79.

Affected Systems

Any WordPress site running the Customer Reviews for WooCommerce plugin version 5.122.0 or earlier is affected. The flaw exists in all releases up to and including 5.122.0, regardless of other plugin or WordPress versions.

Risk and Exploitability

The vulnerability has a CVSS base score of 7.2, indicating a high risk when the conditions are met. Although EPSS data is not available, the flaw is exploitable by unauthenticated users who can submit a review with a malicious author name. Attackers must have the image attachment option (ivole_attach_image) enabled to upload a maliciously named image via the public wp_ajax_nopriv_cr_upload_local_images_frontend endpoint. The flaw is not listed in the CISA KEV catalog, but it can be leveraged remotely without authentication, which makes it a serious threat for any exposed WordPress site with the plugin enabled.

Generated by OpenCVE AI on October 2, 2026 at 08:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Customer Reviews for WooCommerce plugin to a version newer than 5.122.0 (or apply the vendor's patch if available).
  • If an upgrade is not immediately possible, disable the image attachment feature by turning off ivole_attach_image to prevent the vulnerability’s exploitation path.
  • Ensure all user input for the Comment Author Name field is sanitized and properly escaped before it is stored or displayed, thereby mitigating the stored XSS vulnerability.

Generated by OpenCVE AI on October 2, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint.
Title Customer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:20.600Z

Reserved: 2026-09-24T19:50:50.651Z

Link: CVE-2026-97663

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:06.000

Modified: 2026-10-02T08:17:06.000

Link: CVE-2026-97663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')