HomeWordPress vulnerabilitiesCustomer Reviews for WooCommerce
Customer Reviews for WooCommerce vulnerabilities
Customer Reviews for WooCommerce has 23 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.
- Known vulnerabilities
- 23
- Active installs
- 80,000+
- Latest version
- 5.123.0
- Last updated
- 28 Sep 2026
- Most recent
- 2 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-97663 | High 7.2 | Up to 5.122.0 | Fixed in a later version (latest 5.123.0) | 5 d ago |
| Broken access control CVE-2026-89055 | Critical 9.1 | Up to 5.120.0 | Fixed in a later version (latest 5.123.0) | 12 d ago |
| Cross-site scripting (XSS) CVE-2026-76585 | High 8.8 | Before 5.118.0 | Fixed in 5.118.0 | 30 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-6176 | High 7.2 | Up to 5.106.0 | Fixed in a later version (latest 5.123.0) | 28 Aug 2026 |
| Broken access control CVE-2026-14941 | Medium 5.4 | Before 5.116.0 | Fixed in 5.116.0 | 10 Aug 2026 |
| Arbitrary file upload CVE-2026-12684 | Medium 6.5 | Before 5.113.0 | Fixed in 5.113.0 | 16 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-13771 | Medium 6.4 | Up to 5.113.0 | Fixed in a later version (latest 5.123.0) | 9 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-3355 | Medium 6.1 | Up to 5.101.0 | Fixed in a later version (latest 5.123.0) | 16 Apr 2026 |
| Authentication bypass CVE-2026-4664 | Medium 5.3 | Up to 5.103.0 | Fixed in a later version (latest 5.123.0) | 10 Apr 2026 |
| Cross-site scripting (XSS) CVE-2026-1316 | High 7.2 | Up to 5.97.0 | Fixed in a later version (latest 5.123.0) | 12 Feb 2026 |
| Cross-site scripting (XSS) CVE-2025-14891 | Medium 6.4 | Up to 5.93.1 | Fixed in a later version (latest 5.123.0) | 7 Jan 2026 |
| Cross-site scripting (XSS) CVE-2025-5720 | Medium 6.4 | Up to 5.80.2 | Fixed in a later version (latest 5.123.0) | 31 Jul 2025 |
| Broken access control CVE-2024-10614 | Medium 4.3 | Before 5.61.1 | Fixed in 5.61.1 | 16 Nov 2024 |
| Cross-site scripting (XSS) CVE-2024-3731 | Medium 6.1 | Before 5.48.0 | Fixed in 5.48.0 | 19 Apr 2024 |
| Broken access control CVE-2024-3243 | Medium 4.3 | Before 5.47.0 | Fixed in 5.47.0 | 16 Apr 2024 |
| Broken access control CVE-2024-3869 | Medium 4.3 | Before 5.47.0 | Fixed in 5.47.0 | 16 Apr 2024 |
| Broken access control CVE-2024-1044 | Medium 5.3 | Before 5.39.0 | Fixed in 5.39.0 | 29 Feb 2024 |
| Cross-site scripting (XSS) CVE-2023-0079 | Medium 5.4 | Before 5.17.0 | Fixed in 5.17.0 | 16 Jan 2024 |
| Remote code execution CVE-2023-6979 | High 8.8 | Up to 5.38.9 | Fixed in a later version (latest 5.123.0) | 11 Jan 2024 |
| Remote code execution CVE-2023-0080 | High 8.8 | Before 5.16.0 | Fixed in 5.16.0 | 13 Feb 2023 |
| Broken access control CVE-2022-38134 | Medium 4.3 | Up to 5.3.5 | Fixed in a later version (latest 5.123.0) | 23 Sep 2022 |
| Cross-site request forgery (CSRF) CVE-2022-38470 | Medium 4.3 | Up to 5.3.5 | Fixed in a later version (latest 5.123.0) | 23 Sep 2022 |
| Sensitive data exposure CVE-2022-40194 | Medium 5.3 | Up to 5.3.5 | Fixed in a later version (latest 5.123.0) | 23 Sep 2022 |
Read the published descriptions
- CVE-2026-97663, 2 Oct 2026
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint. CVE record
- CVE-2026-89055, 25 Sep 2026
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library - including administrator-owned product images, logos, and documents - by injecting their IDs into a review that is later trashed and purged. Exploitation requires a public review-form link (a 13-hex formId distributed to customers via e-mail), which exposes the nonce needed to reach the handler without any WordPress account or session. CVE record
- CVE-2026-76585, 30 Aug 2026
- The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks. CVE record
- CVE-2026-6176, 28 Aug 2026
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review submissions from unauthenticated users through the 'cr_local_forms_submit' AJAX action without sanitizing HTML content before storing it via wp_insert_comment(), and later renders this stored content on product pages through comment_text() without proper escaping. This makes it possible for unauthenticated attackers with a valid review form URL (obtainable through review reminder emails sent to customers who placed orders) to inject arbitrary web scripts in pages that will execute whenever a user accesses the affected product page. CVE record
- CVE-2026-14941, 10 Aug 2026
- The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration. CVE record
- CVE-2026-12684, 16 Jul 2026
- The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist) to the Media Library and create attachment posts, leading to media library pollution and disk space exhaustion. CVE record
- CVE-2026-13771, 9 Jul 2026
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-3355, 16 Apr 2026
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2026-4664, 10 Apr 2026
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict equality (`===`), without verifying that the stored key is non-empty. For orders where no review reminder email has been sent, the `ivole_secret_key` meta is not set, causing `get_meta()` to return an empty string. An attacker can supply `key: ""` to match this empty value and bypass the permission check. This makes it possible for unauthenticated attackers to submit, modify, and inject product reviews on any product - including products not associated with the referenced order - via the REST API endpoint `POST /ivole/v1/review`. Reviews are auto-approved by default since `ivole_enable_moderation` defaults to `"no"`. CVE record
- CVE-2026-1316, 12 Feb 2026
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests' is enabled) to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-14891, 7 Jan 2026
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. While it is possible to invoke the AJAX action without authentication, the attacker would need to know a valid form ID, which requires them to place an order. This vulnerability can be exploited by unauthenticated attackers if guest checkout is enabled. However, the form ID still needs to be obtained through placing an order. CVE record
- CVE-2025-5720, 31 Jul 2025
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-10614, 16 Nov 2024
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import or check on the status. CVE record
- CVE-2024-3731, 19 Apr 2024
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2024-3243, 16 Apr 2024
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails. CVE record
- CVE-2024-3869, 16 Apr 2024
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes. CVE record
- CVE-2024-1044, 29 Feb 2024
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email addresses regardless of whether reviews are globally enabled. CVE record
- CVE-2023-0079, 16 Jan 2024
- The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. CVE record
- CVE-2023-6979, 11 Jan 2024
- The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
- CVE-2023-0080, 13 Feb 2023
- The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability. CVE record
- CVE-2022-38134, 23 Sep 2022
- Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. CVE record
- CVE-2022-38470, 23 Sep 2022
- Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. CVE record
- CVE-2022-40194, 23 Sep 2022
- Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress CVE record
What to do if you run Customer Reviews for WooCommerce
If you run Customer Reviews for WooCommerce, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Customer Reviews for WooCommerce vulnerabilities
Free. We email you when a new vulnerability is published for Customer Reviews for WooCommerce, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.