WordPress · Customer Reviews For Woocommerce · CVE-2026-76585
**Name of the Vulnerable Software and Affected Versions**
Customer Reviews for WooCommerce versions prior to 5.118.0
**Description**
Unauthenticated users can perform Stored Cross-Site Scripting (XSS) attacks because the plugin fails to sanitize and escape the content of customer reviews. This occurs via the `comment` parameter received through one of its endpoints. Stored Cross-Site Scripting is a type of attack where malicious scripts are permanently stored on the target server.
**Recommendations**
Update Customer Reviews for WooCommerce to version 5.118.0 or later.
Avoid using the `comment` parameter in the affected endpoint until the update is applied.