WordPress · Customer Reviews For Woocommerce · CVE-2026-89055
**Name of the Vulnerable Software and Affected Versions**
Customer Reviews for WooCommerce versions prior to 5.120.1
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can permanently delete arbitrary attachments from the Media Library, such as administrator-owned product images, logos, and documents. This is achieved by injecting attachment IDs into a review that is subsequently trashed and purged. The attack targets the `cr local forms submit` handler and requires a public review-form link containing a 13-hex `formId` to expose the nonce needed to access the handler without a WordPress account or session.
**Recommendations**
Update to a version later than 5.120.0.