CVE-2026-76585
moderateUnauthenticated Stored XSS in Customer Reviews for WooCommerce WordPress Plugin
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 fails to sanitise and escape the content of customer reviews submitted through one of its endpoints. An unauthenticated attacker can submit a review containing malicious HTML/JavaScript, which is then stored and executed in the browser of anyone who views the review content, such as an administrator moderating reviews or a customer browsing the shop. By running attacker-controlled JavaScript in an admin's or visitor's browser, the attacker can perform actions in that user's session, such as creating backdoor admin users, altering pages, or redirecting visitors. Any WooCommerce store running the plugin in a version below 5.118.0 is affected. There is currently no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, so no in-the-wild exploitation is known.
What to do: Update the plugin to version 5.118.0 or later. Until patched, restrict or disable unauthenticated review submission through the affected endpoint and moderate incoming reviews manually; after patching, review stored customer reviews for injected HTML/script tags and watch for unexpected admin users or modified site content that could indicate exploitation.
| CusRev Customer Reviews for WooCommerce (WordPress plugin) | before 5.118.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.