Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form
high
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review sub...
- CVSS:
- 7.2
- Affected:
- up to 5.106.0
- Fixed in:
- 5.107.0
- Disclosed:
- Aug 27, 2026
CVE-2026-6176 on NVD →
Customer Reviews for WooCommerce <= 5.115.0 - Missing Authorization
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.115.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.115.0
- Fixed in:
- 5.116.0
- Disclosed:
- Aug 6, 2026
CVE-2026-14941 on NVD →
Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acce...
- CVSS:
- 6.4
- Affected:
- up to 5.113.0
- Fixed in:
- 5.114.0
- Disclosed:
- Jul 8, 2026
CVE-2026-13771 on NVD →
Customer Reviews for WooCommerce <= 5.110.1 - Unauthenticated Stored Cross-Site Scripting
high
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.110.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe...
- CVSS:
- 7.2
- Affected:
- up to 5.110.1
- Fixed in:
- 5.111.0
- Disclosed:
- Jun 24, 2026
CVE-2026-56043 on NVD →
Customer Reviews for WooCommerce <= 5.101.0 - Reflected Cross-Site Scripting via 'crsearch'
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- CVSS:
- 6.1
- Affected:
- up to 5.101.0
- Fixed in:
- 5.102.0
- Disclosed:
- Apr 15, 2026
CVE-2026-3355 on NVD →
Customer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' Parameter
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict equal...
- CVSS:
- 5.3
- Affected:
- up to 5.103.0
- Fixed in:
- 5.104.0
- Disclosed:
- Apr 9, 2026
CVE-2026-4664 on NVD →
Customer Reviews for WooCommerce <= 5.97.0 - Unauthenticated Stored Cross-Site Scripting via media[].href Parameter
high
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests' is...
- CVSS:
- 7.2
- Affected:
- up to 5.97.0
- Fixed in:
- 5.98.0
- Disclosed:
- Feb 12, 2026
CVE-2026-1316 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.94.0
unknown
[en] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level acc...
- Affected:
- up to 5.94.0
- Fixed in:
- 5.94.0
- Disclosed:
- Jan 7, 2026
CVE-2025-14891 on NVD →
Customer Reviews for WooCommerce <= 5.93.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName Parameter
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access a...
- CVSS:
- 6.4
- Affected:
- up to 5.93.1
- Fixed in:
- 5.94.0
- Disclosed:
- Jan 6, 2026
CVE-2025-14891 on NVD →
Customer Reviews for WooCommerce <= 5.80.2 - Unauthenticated Stored Cross-Site Scripting via `author` Parameter
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 5.80.2
- Fixed in:
- 5.81.0
- Disclosed:
- Jul 30, 2025
CVE-2025-5720 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.36.1
unknown
[en] Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through 5.36.0.
- Affected:
- up to 5.36.1
- Fixed in:
- 5.36.1
- Disclosed:
- Jan 2, 2025
CVE-2023-45101 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.62.0
unknown
[en] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and im...
- Affected:
- up to 5.62.0
- Fixed in:
- 5.62.0
- Disclosed:
- Nov 16, 2024
CVE-2024-10614 on NVD →
Customer Reviews for WooCommerce <= 5.61.0 - Missing Authorization to Authenticated (Subscriber+) Import Cancellation
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import...
- CVSS:
- 4.3
- Affected:
- up to 5.61.0
- Fixed in:
- 5.62.0
- Disclosed:
- Nov 15, 2024
CVE-2024-10614 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.48.0
unknown
[en] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- Affected:
- up to 5.48.0
- Fixed in:
- 5.48.0
- Disclosed:
- Apr 19, 2024
CVE-2024-3731 on NVD →
Customer Reviews for WooCommerce <= 5.47.0 - Reflected Cross-Site Scripting via 's'
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 5.47.0
- Fixed in:
- 5.48.0
- Disclosed:
- Apr 18, 2024
CVE-2024-3731 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.47.0
unknown
[en] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send...
- Affected:
- up to 5.47.0
- Fixed in:
- 5.47.0
- Disclosed:
- Apr 16, 2024
CVE-2024-3243 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.47.0
unknown
[en] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
- Affected:
- up to 5.47.0
- Fixed in:
- 5.47.0
- Disclosed:
- Apr 16, 2024
CVE-2024-3869 on NVD →
Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbi...
- CVSS:
- 4.3
- Affected:
- up to 5.46.0
- Fixed in:
- 5.47.0
- Disclosed:
- Apr 15, 2024
CVE-2024-3243 on NVD →
Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Coupon Search
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
- CVSS:
- 4.3
- Affected:
- up to 5.46.0
- Fixed in:
- 5.47.0
- Disclosed:
- Apr 15, 2024
CVE-2024-3869 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.38.2
unknown
[en] Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.
- Affected:
- up to 5.38.2
- Fixed in:
- 5.38.2
- Disclosed:
- Feb 28, 2024
CVE-2023-51692 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.39.0
unknown
[en] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email a...
- Affected:
- up to 5.39.0
- Fixed in:
- 5.39.0
- Disclosed:
- Feb 20, 2024
CVE-2024-1044 on NVD →
Customer Reviews for WooCommerce <= 5.38.10 - Improper Authorization via submit_review
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email addres...
- CVSS:
- 5.3
- Affected:
- up to 5.38.12
- Fixed in:
- 5.39.0
- Disclosed:
- Feb 6, 2024
CVE-2024-1044 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.17.0
unknown
[en] The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 5.17.0
- Fixed in:
- 5.17.0
- Disclosed:
- Jan 16, 2024
CVE-2023-0079 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.38.10
unknown
[en] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to u...
- Affected:
- up to 5.38.10
- Fixed in:
- 5.38.10
- Disclosed:
- Jan 11, 2024
CVE-2023-6979 on NVD →
Customer Reviews for WooCommerce <= 5.38.9 - Authenticated (Author+) Arbitrary File Upload
high
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload...
- CVSS:
- 8.8
- Affected:
- up to 5.38.9
- Fixed in:
- 5.38.10
- Disclosed:
- Jan 9, 2024
CVE-2023-6979 on NVD →
Customer Reviews for WooCommerce <= 5.38.1 - Missing Authorization via CR_Manual
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple functions in the 'CR_Manual' class versions up to, and including, 5.38.1. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 5.3
- Affected:
- up to 5.38.1
- Fixed in:
- 5.38.2
- Disclosed:
- Dec 27, 2023
CVE-2023-51692 on NVD →
Customer Reviews for WooCommerce <= 5.38.1 - Cross-Site Request Forgery via manual review reminders
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 5.38.2 (exclusive). This is due to missing or incorrect nonce validation on the manual_review_reminder, manual_wa_review_reminder, and manual_review_reminder_conf functions. This makes it possible...
- CVSS:
- 4.3
- Affected:
- up to 5.38.2
- Fixed in:
- 5.38.2
- Disclosed:
- Nov 19, 2023
Customer Reviews for WooCommerce <= 5.38.1 - Missing Authorization via manual review reminders
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the manual_review_reminder, manual_wa_review_reminder, and manual_review_reminder_conf functions in all versions up to 5.38.2 (exclusive). This makes it possible for authenti...
- CVSS:
- 4.3
- Affected:
- up to 5.38.2
- Fixed in:
- 5.38.2
- Disclosed:
- Nov 19, 2023
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.38.2
unknown
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the manual_review_reminder, manual_wa_review_reminder, and manual_review_reminder_conf functions in all versions up to 5.38.2 (exclusive). This makes it possible for authenti...
- Affected:
- up to 5.38.2
- Fixed in:
- 5.38.2
- Disclosed:
- Nov 19, 2023
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.38.2
unknown
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 5.38.2 (exclusive). This is due to missing or incorrect nonce validation on the manual_review_reminder, manual_wa_review_reminder, and manual_review_reminder_conf functions. This makes it possible...
- Affected:
- up to 5.38.2
- Fixed in:
- 5.38.2
- Disclosed:
- Nov 19, 2023
Customer Reviews for WooCommerce <= 5.36.0 - Missing Authorization in Reviews Exporter
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the check_progress and cancel_export functions in versions up to, and including, 5.36.0. This makes it possible for authenticated attackers, with subscribe...
- CVSS:
- 5.4
- Affected:
- up to 5.36.0
- Fixed in:
- 5.36.1
- Disclosed:
- Oct 6, 2023
CVE-2023-45101 on NVD →
Customer Reviews for WooCommerce <= 5.36.0 - Missing Authorization
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX actions in versions up to, and including, 5.36.0. This makes it possible for authenticated attackers with subscriber level access to cancel exports and obtain...
- CVSS:
- 4.3
- Affected:
- up to 5.36.1
- Fixed in:
- 5.36.1
- Disclosed:
- Oct 4, 2023
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.36.1
unknown
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX actions in versions up to, and including, 5.36.0. This makes it possible for authenticated attackers with subscriber level access to cancel exports and obtain...
- Affected:
- up to 5.36.1
- Fixed in:
- 5.36.1
- Disclosed:
- Oct 4, 2023
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.16.0
unknown
[en] The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could a...
- Affected:
- up to 5.16.0
- Fixed in:
- 5.16.0
- Disclosed:
- Feb 13, 2023
CVE-2023-0080 on NVD →
Customer Reviews for WooCommerce <= 5.16.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via either a ‘color_ex_brdr’ or 'color_ex_bcrd' shortcode attributes in versions up to, and including, 5.16.0 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level at...
- CVSS:
- 6.4
- Affected:
- up to 5.16.0
- Fixed in:
- 5.17.0
- Disclosed:
- Jan 24, 2023
CVE-2023-0079 on NVD →
Customer Reviews for WooCommerce <= 5.15.0 - Authenticated (Subscriber+) Local File Inclusion
high
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.15.0 via a shortcode attribute. This allows subscriber-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 8.1
- Affected:
- up to 5.15.0
- Fixed in:
- 5.16.0
- Disclosed:
- Jan 23, 2023
CVE-2023-0080 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.3.6
unknown
[en] Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- Sep 23, 2022
CVE-2022-40194 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.3.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- Sep 23, 2022
CVE-2022-38470 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.3.6
unknown
[en] Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- Sep 23, 2022
CVE-2022-38134 on NVD →
Customer Reviews for WooCommerce <= 5.3.5 - Multiple Unprotected AJAX Actions
medium
The Customer Reviews for WooCommerce plugin contains several AJAX actions that are not protected by capability or nonce checks in versions up to, and including, 5.3.5. This allows authenticated users, such as subscribers, to perform actions that should be restricted to administrators, such as exporting reviews and send...
- CVSS:
- 5.4
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.6
- Disclosed:
- Sep 22, 2022
CVE-2022-38134 on NVD →
Customer Reviews for WooCommerce <= 5.3.5 - Cross-Site Request Forgery
medium
The Customer Reviews for WooCommerce plugin contains several AJAX actions that are not protected by capability or nonce checks in versions up to, and including, 5.3.5. This allows unauthenticated attackers to perform actions that should be restricted to administrators, such as exporting reviews and sending test emails,...
- CVSS:
- 5.4
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.6
- Disclosed:
- Sep 22, 2022
CVE-2022-38470 on NVD →
Customer Reviews for WooCommerce <= 5.3.5 - Sensitive Data Exposure
medium
The Customer Reviews for WooCommerce plugin contains several AJAX actions that are not protected by capability or nonce checks in versions up to, and including, 5.3.5. This allows authenticated users, such as subscribers, to perform actions that should be restricted to administrators, such as exporting sensitive data i...
- CVSS:
- 4.3
- Affected:
- up to 5.3.5
- Fixed in:
- 5.3.6
- Disclosed:
- Sep 22, 2022
CVE-2022-40194 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.38.2
unknown
The plugin is vulnerable to unauthorized modification of data due to a missing capability check on the manual_review_reminder, manual_wa_review_reminder, and manual_review_reminder_conf functions in all versions up to 5.38.2 (exclusive). This makes it possible for authenticated attackers, with subscriber access and abo...
- Affected:
- up to 5.38.2
- Fixed in:
- 5.38.2
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.38.2
unknown
The plugin is vulnerable to Cross-Site Request Forgery in all versions up to 5.38.2 (exclusive). This is due to missing or incorrect nonce validation on the manual_review_reminder, manual_wa_review_reminder, and manual_review_reminder_conf functions. This makes it possible for unauthenticated attackers to configure and...
- Affected:
- up to 5.38.2
- Fixed in:
- 5.38.2
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.81.0
unknown
- Affected:
- up to 5.81.0
- Fixed in:
- 5.81.0
CVE-2025-5720 on NVD →
Customer Reviews for WooCommerce [customer-reviews-woocommerce] < 5.36.1
unknown
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX actions in versions up to, and including, 5.36.0. This makes it possible for authenticated attackers with subscriber level access to cancel exports and obtain...
- Affected:
- up to 5.36.1
- Fixed in:
- 5.36.1