rootpwn

medium · CVSS v3 6.1 · EPSS 0.00332

CVE-2026-11608

The WP Customer Reviews plugin for WordPress is vulnerable to reflected cross-site scripting due to improper handling of the 'wpcr3_fname' p

Overview

The WP Customer Reviews plugin for WordPress is vulnerable to reflected cross-site scripting due to improper handling of the 'wpcr3_fname' parameter. This flaw allows unauthenticated attackers to execute arbitrary scripts in a victim's browser by tricking them into clicking a specifically crafted link.

Description

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Impact

Successful exploitation compromises the integrity and confidentiality of the user's session, potentially leading to unauthorized actions or data theft. If an administrative user is targeted, the attacker could potentially gain elevated access to the WordPress site. The impact is restricted to the client-side execution environment of the interacting user.

Remediation

Update the WP Customer Reviews plugin to version 3.7.9 or the latest available version immediately to apply necessary sanitization patches. Organizations unable to update should implement Web Application Firewall (WAF) rules to inspect and block malicious scripts within the 'wpcr3_fname' query parameter.

Risk context

This vulnerability is rated as Medium severity with a CVSS score of 6.1. While the EPSS score of 0.00332 suggests a lower probability of mass exploitation compared to critical remote code execution flaws, the reliance on social engineering makes it a targeted risk for high-traffic WordPress sites.

Affected products

  • WordPress
  • WP Customer Reviews plugin <= 3.7.8

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
EPSS
0.00332

XSS WordPress Plugin Reflected XSS WP Customer Reviews CVE-2026-11608

← All CVEs