Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesCustomer Reviews for WooCommerce

Customer Reviews for WooCommerce vulnerabilities

Customer Reviews for WooCommerce has 23 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.

Known vulnerabilities
23
Active installs
80,000+
Latest version
5.123.0
Last updated
28 Sep 2026
Most recent
2 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-97663
High 7.2Up to 5.122.0Fixed in a later version (latest 5.123.0)5 d ago
Broken access control
CVE-2026-89055
Critical 9.1Up to 5.120.0Fixed in a later version (latest 5.123.0)12 d ago
Cross-site scripting (XSS)
CVE-2026-76585
High 8.8Before 5.118.0Fixed in 5.118.030 Aug 2026
Cross-site scripting (XSS)
CVE-2026-6176
High 7.2Up to 5.106.0Fixed in a later version (latest 5.123.0)28 Aug 2026
Broken access control
CVE-2026-14941
Medium 5.4Before 5.116.0Fixed in 5.116.010 Aug 2026
Arbitrary file upload
CVE-2026-12684
Medium 6.5Before 5.113.0Fixed in 5.113.016 Jul 2026
Cross-site scripting (XSS)
CVE-2026-13771
Medium 6.4Up to 5.113.0Fixed in a later version (latest 5.123.0)9 Jul 2026
Cross-site scripting (XSS)
CVE-2026-3355
Medium 6.1Up to 5.101.0Fixed in a later version (latest 5.123.0)16 Apr 2026
Authentication bypass
CVE-2026-4664
Medium 5.3Up to 5.103.0Fixed in a later version (latest 5.123.0)10 Apr 2026
Cross-site scripting (XSS)
CVE-2026-1316
High 7.2Up to 5.97.0Fixed in a later version (latest 5.123.0)12 Feb 2026
Cross-site scripting (XSS)
CVE-2025-14891
Medium 6.4Up to 5.93.1Fixed in a later version (latest 5.123.0)7 Jan 2026
Cross-site scripting (XSS)
CVE-2025-5720
Medium 6.4Up to 5.80.2Fixed in a later version (latest 5.123.0)31 Jul 2025
Broken access control
CVE-2024-10614
Medium 4.3Before 5.61.1Fixed in 5.61.116 Nov 2024
Cross-site scripting (XSS)
CVE-2024-3731
Medium 6.1Before 5.48.0Fixed in 5.48.019 Apr 2024
Broken access control
CVE-2024-3243
Medium 4.3Before 5.47.0Fixed in 5.47.016 Apr 2024
Broken access control
CVE-2024-3869
Medium 4.3Before 5.47.0Fixed in 5.47.016 Apr 2024
Broken access control
CVE-2024-1044
Medium 5.3Before 5.39.0Fixed in 5.39.029 Feb 2024
Cross-site scripting (XSS)
CVE-2023-0079
Medium 5.4Before 5.17.0Fixed in 5.17.016 Jan 2024
Remote code execution
CVE-2023-6979
High 8.8Up to 5.38.9Fixed in a later version (latest 5.123.0)11 Jan 2024
Remote code execution
CVE-2023-0080
High 8.8Before 5.16.0Fixed in 5.16.013 Feb 2023
Broken access control
CVE-2022-38134
Medium 4.3Up to 5.3.5Fixed in a later version (latest 5.123.0)23 Sep 2022
Cross-site request forgery (CSRF)
CVE-2022-38470
Medium 4.3Up to 5.3.5Fixed in a later version (latest 5.123.0)23 Sep 2022
Sensitive data exposure
CVE-2022-40194
Medium 5.3Up to 5.3.5Fixed in a later version (latest 5.123.0)23 Sep 2022
Read the published descriptions
CVE-2026-97663, 2 Oct 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint. CVE record
CVE-2026-89055, 25 Sep 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library - including administrator-owned product images, logos, and documents - by injecting their IDs into a review that is later trashed and purged. Exploitation requires a public review-form link (a 13-hex formId distributed to customers via e-mail), which exposes the nonce needed to reach the handler without any WordPress account or session. CVE record
CVE-2026-76585, 30 Aug 2026
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks. CVE record
CVE-2026-6176, 28 Aug 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review submissions from unauthenticated users through the 'cr_local_forms_submit' AJAX action without sanitizing HTML content before storing it via wp_insert_comment(), and later renders this stored content on product pages through comment_text() without proper escaping. This makes it possible for unauthenticated attackers with a valid review form URL (obtainable through review reminder emails sent to customers who placed orders) to inject arbitrary web scripts in pages that will execute whenever a user accesses the affected product page. CVE record
CVE-2026-14941, 10 Aug 2026
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration. CVE record
CVE-2026-12684, 16 Jul 2026
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist) to the Media Library and create attachment posts, leading to media library pollution and disk space exhaustion. CVE record
CVE-2026-13771, 9 Jul 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-3355, 16 Apr 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2026-4664, 10 Apr 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict equality (`===`), without verifying that the stored key is non-empty. For orders where no review reminder email has been sent, the `ivole_secret_key` meta is not set, causing `get_meta()` to return an empty string. An attacker can supply `key: ""` to match this empty value and bypass the permission check. This makes it possible for unauthenticated attackers to submit, modify, and inject product reviews on any product - including products not associated with the referenced order - via the REST API endpoint `POST /ivole/v1/review`. Reviews are auto-approved by default since `ivole_enable_moderation` defaults to `"no"`. CVE record
CVE-2026-1316, 12 Feb 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests' is enabled) to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-14891, 7 Jan 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. While it is possible to invoke the AJAX action without authentication, the attacker would need to know a valid form ID, which requires them to place an order. This vulnerability can be exploited by unauthenticated attackers if guest checkout is enabled. However, the form ID still needs to be obtained through placing an order. CVE record
CVE-2025-5720, 31 Jul 2025
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-10614, 16 Nov 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import or check on the status. CVE record
CVE-2024-3731, 19 Apr 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2024-3243, 16 Apr 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails. CVE record
CVE-2024-3869, 16 Apr 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes. CVE record
CVE-2024-1044, 29 Feb 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email addresses regardless of whether reviews are globally enabled. CVE record
CVE-2023-0079, 16 Jan 2024
The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. CVE record
CVE-2023-6979, 11 Jan 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
CVE-2023-0080, 13 Feb 2023
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability. CVE record
CVE-2022-38134, 23 Sep 2022
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. CVE record
CVE-2022-38470, 23 Sep 2022
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. CVE record
CVE-2022-40194, 23 Sep 2022
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress CVE record

What to do if you run Customer Reviews for WooCommerce

If you run Customer Reviews for WooCommerce, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Customer Reviews for WooCommerce vulnerabilities

Free. We email you when a new vulnerability is published for Customer Reviews for WooCommerce, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support