Junglewise Threat Intelligence

CVE-2026-14942: Customer Reviews for WooCommerce privilege escalation attempt (rejected)

CVE-2026-14942 · Severity: info · Published 2026-08-28

Vendors: WordPress.org.

Executive brief

A vulnerability was reported in the Customer Reviews for WooCommerce WordPress plugin but was ultimately rejected and withdrawn. The reported issue could not be validated because the precondition required for exploitation—an attacker obtaining a review form identifier without legitimate access—could not be demonstrated as feasible. No advisory or patch was issued.

Technical details

The vulnerability was classified as a potential privilege escalation or unauthorized access issue in the Customer Reviews for WooCommerce plugin. The attack would require an attacker to obtain a review form identifier belonging to a customer they do not have legitimate access to. The report was withdrawn because this precondition could not be reliably demonstrated in practice, casting doubt on the exploitability of the underlying issue. No CVE was officially assigned, and no patch or mitigation was released.

Affected products

  • Wordpress.org Customer Reviews for WooCommerce

Timeline

  • 2026-08-28: disclosed