Junglewise Threat Intelligence

CVE-2026-11608: WP Customer Reviews reflected cross-site scripting

CVE-2026-11608 · Severity: medium · CVSS 6.1 · Published 2026-09-19

Executive brief

WP Customer Reviews is a WordPress plugin that collects and displays customer reviews on websites. A flaw in the plugin allows attackers to inject malicious scripts into web pages via a crafted link; if a user clicks the link, their session could be hijacked, credentials stolen, or malware delivered to their browser.

Technical details

Reflected cross-site scripting vulnerability in the 'wpcr3_fname' parameter due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary JavaScript that executes in a victim's browser when they click a malicious link. The flaw affects all versions up to and including 3.7.8.

Affected products

  • Badmitts WP Customer Reviews up to and including 3.7.8

Timeline

  • 2026-09-19: disclosed

References