PT-2026-104500 · WordPress · Woocommerce Photo Reviews

·

CVE-2026-101923

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Photo Reviews for WooCommerce versions prior to 1.2.31
Description An issue allows unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments. The flaw occurs because the plugin stores attacker-controlled post IDs from the wcpr image upload id parameter of a public review submission into the review's reviews-images comment meta without verifying ownership. When an administrator deletes the review, or when the wp scheduled delete cron task empties the comment trash, the delete reviews image() function calls wp delete post( $id, true ) on every stored ID, leading to the deletion of the specified content.
Recommendations Update Photo Reviews for WooCommerce to version 1.2.31 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101923

Affected Products

Woocommerce Photo Reviews