rootpwn

high · CVSS v3 7.2 · EPSS 0.00241

CVE-2026-97663

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to stored XSS via the comment author name field. Unauthenticated att

Overview

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to stored XSS via the comment author name field. Unauthenticated attackers can inject scripts that execute when users view reviews, provided the image attachment feature is enabled. This allows malicious code to run in the context of site visitors.

Description

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint.

Impact

Confidentiality: injected scripts can steal user data or session cookies. Integrity: review content can be altered or malicious content displayed. Availability: not directly affected. Defenders: site owners, administrators, and users of WordPress sites using the plugin.

Remediation

Update the plugin to version 5.122.1 or later. Disable the image attachment feature if not required. Ensure input sanitization and output escaping for review fields. Implement site-wide XSS mitigations such as a strong Content Security Policy.

Risk context

High severity (CVSS 7.2) and low EPSS (0.00241) indicate moderate likelihood but high impact; patching should be prioritized promptly.

Affected products

  • WordPress
  • WooCommerce
  • Customer Reviews for WooCommerce plugin

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00241

XSS WordPress WooCommerce StoredXSS CustomerReviews HighSeverity EPSS

← All CVEs