Executive brief
A vulnerability in the Customer Reviews for WooCommerce plugin, which helps online stores collect and display verified customer feedback, could allow attackers to inject malicious scripts into the website. If a site administrator or visitor views a page containing this malicious content, the attacker could potentially hijack sessions, redirect users to fraudulent sites, or deface the store. This issue affects all versions up to 5.110.1 and can be triggered by unauthenticated users.
Technical details
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation (CWE-79). An unauthenticated attacker can send a specially crafted request to a vulnerable site, which, if executed by a victim (typically an administrator or site visitor), allows the attacker to run arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, unauthorized actions on behalf of the user, or the delivery of malicious payloads. The vulnerability is present in versions up to and including 5.110.1 and was addressed in version 5.111.0.
Affected products
- CusRev Customer Reviews for WooCommerce <= 5.110.1
Timeline
- 2026-05-03: other: Reported by researcher daroo
- 2026-06-24: advisory: Patchstack advisory published
- 2026-06-26: disclosed: NVD publication date