high · CVSS v3 7.2 · EPSS 0.00241
CVE-2026-97663
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to stored XSS via the comment author name field. Unauthenticated att
Overview
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to stored XSS via the comment author name field. Unauthenticated attackers can inject scripts that execute when users view reviews, provided the image attachment feature is enabled. This allows malicious code to run in the context of site visitors.
Description
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint.
Impact
Confidentiality: injected scripts can steal user data or session cookies. Integrity: review content can be altered or malicious content displayed. Availability: not directly affected. Defenders: site owners, administrators, and users of WordPress sites using the plugin.
Remediation
Update the plugin to version 5.122.1 or later. Disable the image attachment feature if not required. Ensure input sanitization and output escaping for review fields. Implement site-wide XSS mitigations such as a strong Content Security Policy.
Risk context
High severity (CVSS 7.2) and low EPSS (0.00241) indicate moderate likelihood but high impact; patching should be prioritized promptly.
Affected products
- WordPress
- WooCommerce
- Customer Reviews for WooCommerce plugin
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00241