PT-2026-83525 · WordPress · Customer Reviews For Woocommerce

·

CVE-2026-76585

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Customer Reviews for WooCommerce versions prior to 5.118.0
Description Unauthenticated users can perform Stored Cross-Site Scripting (XSS) attacks because the plugin fails to sanitize and escape the content of customer reviews. This occurs via the comment parameter received through one of its endpoints. Stored Cross-Site Scripting is a type of attack where malicious scripts are permanently stored on the target server.
Recommendations Update Customer Reviews for WooCommerce to version 5.118.0 or later. Avoid using the comment parameter in the affected endpoint until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76585

Affected Products

Customer Reviews For Woocommerce