PT-2026-98367 · WordPress · Customer Reviews For Woocommerce

·

CVE-2026-89055

·

Published

2026-09-25

·

Updated

2026-09-27

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Customer Reviews for WooCommerce versions prior to 5.120.1
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can permanently delete arbitrary attachments from the Media Library, such as administrator-owned product images, logos, and documents. This is achieved by injecting attachment IDs into a review that is subsequently trashed and purged. The attack targets the cr local forms submit handler and requires a public review-form link containing a 13-hex formId to expose the nonce needed to access the handler without a WordPress account or session.
Recommendations Update to a version later than 5.120.0.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89055

Affected Products

Customer Reviews For Woocommerce