Junglewise Threat Intelligence

CVE-2026-14941: Customer Reviews for WooCommerce missing authorization checks in AJAX handlers

CVE-2026-14941 · Severity: medium · CVSS 5.4 · Published 2026-08-10

Technologies: WP Evotech Customer Reviews for WooCommerce.

Executive brief

The Customer Reviews for WooCommerce WordPress plugin fails to properly verify user permissions on several administrative settings functions. This allows low-privileged users, such as subscribers or customers, to change plugin configuration, modify email sender settings, and read sensitive store configuration details—potentially enabling email spoofing and information disclosure about the online store.

Technical details

The plugin does not perform nonce or capability checks on multiple AJAX actions (cr_settings_hide_banner, ivole_check_license_email_ajax, cr_verify_email_ajax, cr_verify_dkim_ajax, ivole_check_license_ajax, cr_check_age_restriction_ajax), allowing any authenticated user with Subscriber-level permissions to invoke administrative handlers. An attacker with a Subscriber or customer account can update the ivole_hidden_banners option, modify the ivole_email_from setting, and retrieve sensitive store configuration including license state, sender email, and sender name via AJAX POST requests. The vulnerability requires authentication (WordPress session cookie) but no additional CSRF protection or permission validation. The plugin was patched in version 5.116.0, where all affected actions now properly check capabilities and reject unauthorized access.

Affected products

  • WP Evotech Customer Reviews for WooCommerce before 5.116.0

Timeline

  • 2026-08-06: disclosed
  • 2026-08-10: patched: Fixed in version 5.116.0

References