Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Humbertosp

#30258of 57,307
9.1Total CVSS
Vulnerabilities · 1
PT-2026-98367
9.1
2026-09-25
WordPress · Customer Reviews For Woocommerce · CVE-2026-89055
**Name of the Vulnerable Software and Affected Versions** Customer Reviews for WooCommerce versions prior to 5.120.1 **Description** An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can permanently delete arbitrary attachments from the Media Library, such as administrator-owned product images, logos, and documents. This is achieved by injecting attachment IDs into a review that is subsequently trashed and purged. The attack targets the `cr local forms submit` handler and requires a public review-form link containing a 13-hex `formId` to expose the nonce needed to access the handler without a WordPress account or session. **Recommendations** Update to a version later than 5.120.0.