plugin

Wp Customer Reviews Vulnerabilities

19 known security issues reported for the Wp Customer Reviews WordPress plugin. Most recent disclosed Feb 19, 2026.

2 high 6 medium

Running Wp Customer Reviews on your site? Check whether your installed version is affected.

Scan your site free

WP Customer Reviews [wp-customer-reviews] < 3.7.6

unknown

[en] The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

Affected:
up to 3.7.6
Fixed in:
3.7.6
Disclosed:
Feb 19, 2026

CVE-2025-14452 on NVD →

WP Customer Reviews <= 3.7.5 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter

high

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
7.2
Affected:
up to 3.7.5
Fixed in:
3.7.6
Disclosed:
Feb 18, 2026

CVE-2025-14452 on NVD →

WP Customer Reviews [wp-customer-reviews] < 3.7.1

unknown

[en] The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL

Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Apr 15, 2024

CVE-2024-1849 on NVD →

WP Customer Reviews <= 3.7.0 - Authenticated (Contributor+) Malicious Redirect via HTTP-EQUIV Injection

medium

The WP Customer Reviews plugin for WordPress is vulnerable to malicious redirects in all versions up to, and including, 3.7.0. This is due to the plugin not properly validating the Business Name field. This makes it possible for authenticated attackers, with contributor-level access and above, to inject malicious redir...

CVSS:
6.4
Affected:
up to 3.7.0
Fixed in:
3.7.1
Disclosed:
Mar 25, 2024

CVE-2024-1849 on NVD →

WP Customer Reviews [wp-customer-reviews] < 3.6.7

unknown

[en] The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6.6 via the ajax_enabled_posts function. This can allow authenticated attackers to extract sensitive data such as post titles and slugs, including those of protected and trashed posts an...

Affected:
up to 3.6.7
Fixed in:
3.6.7
Disclosed:
Nov 22, 2023

CVE-2023-4686 on NVD →

WP Customer Reviews <= 3.6.6 - Authenticated (Subscriber+) Sensitive Information Exposure

medium

The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6.6 via the ajax_enabled_posts function. This can allow authenticated attackers to extract sensitive data such as post titles and slugs, including those of protected and trashed posts and pag...

CVSS:
4.3
Affected:
up to 3.6.6
Fixed in:
3.6.7
Disclosed:
Oct 31, 2023

CVE-2023-4686 on NVD →

WP Customer Reviews [wp-customer-reviews] < 3.6.7

unknown

[en] The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...

Affected:
up to 3.6.7
Fixed in:
3.6.7
Disclosed:
Oct 20, 2023

CVE-2023-4648 on NVD →

WP Customer Reviews <= 3.6.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject a...

CVSS:
4.4
Affected:
up to 3.6.6
Fixed in:
3.6.7
Disclosed:
Sep 13, 2023

CVE-2023-4648 on NVD →

WP Customer Reviews [wp-customer-reviews] < 3.5.6

unknown

[en] The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled

Affected:
up to 3.5.6
Fixed in:
3.5.6
Disclosed:
May 24, 2021

CVE-2021-24296 on NVD →

WP Customer Reviews <= 3.5.5 - Authenticated Stored Cross-Site Scripting

medium

The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled

CVSS:
4.8
Affected:
up to 3.5.5
Fixed in:
3.5.6
Disclosed:
May 4, 2021

CVE-2021-24296 on NVD →

WP Customer Reviews [wp-customer-reviews] < 3.4.3

unknown

[en] Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Mar 18, 2021

CVE-2021-24135 on NVD →

WP Customer Reviews <= 3.4.2 - Multiple Stored Cross-Site Scripting

medium

Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.

CVSS:
6.1
Affected:
up to 3.4.2
Fixed in:
3.4.3
Disclosed:
Aug 20, 2020

CVE-2021-24135 on NVD →

WP Customer Reviews [wp-customer-reviews] < 3.4.3

unknown

Multiple Unauthenticated and Low Privilege Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities found by Nguyen Anh Tien in WordPress WP Customer Reviews plugin (versions <= 3.4.2).

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Aug 20, 2020

WP Customer Reviews [wp-customer-reviews] < 3.0.9

unknown

[en] The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Aug 21, 2019

CVE-2016-10901 on NVD →

WP Customer Reviews [wp-customer-reviews] < 3.0.9

unknown

[en] The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Aug 21, 2019

CVE-2016-10902 on NVD →

WP Customer Reviews [wp-customer-reviews] < 3.0.9

unknown

Cross-Site Request Forgery (CSRF) Vulnerability was found in WordPress WP Customer Reviews plugin in 3.0.8 version. There's no nonce check to prevent CSRF attack. Update the plugin.

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Apr 6, 2017

WP Customer Reviews [wp-customer-reviews] < 3.0.9

unknown

Cross-Site Request Forgery (CSRF)/Cross-Site Scripting (XSS) Vulnerabilities were found in WordPress WP Customer Reviews plugin in 3.0.8 version. In version 3.0.8, and some earlier versions on this page /wp-admin/admin.php?page=wpcr3_options&tab=form_settings the nonce is not included so there's no prevention against...

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Apr 6, 2017

Customer Reviews < 3.0.9 - Cross-Site Scripting

medium

The Customer Reviews Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_debug_code' parameter in versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Apr 4, 2016

CVE-2016-10901 on NVD →

WP Customer Reviews <= 3.0.8 - Cross-Site Request Forgery

high

The Customer Reviews Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing nonce validation on the 'update_options' function. This makes it possible for unauthenticated attackers modify the plugin's settings and inject malicious web scripts via...

CVSS:
8.8
Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Apr 4, 2014

CVE-2016-10902 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database