Junglewise Threat Intelligence

CVE-2026-8499: Helpfulcrowd Product Reviews auth bypass via PHP type juggling

CVE-2026-8499 · Severity: medium · CVSS 5.3 · Published 2026-06-09

Executive brief

The Helpfulcrowd Product Reviews plugin for WordPress, which manages customer feedback and ratings, contains a security flaw that allows unauthorized individuals to change its settings. By sending a specially crafted request, an attacker can bypass security checks and modify the plugin's configuration without needing a password. This could lead to the disruption of review services or the unauthorized alteration of how the plugin functions on the website.

Technical details

The Helpfulcrowd Product Reviews plugin for WordPress (up to version 1.2.9) is vulnerable to an authorization bypass in the `helpfulcrowd_validate_token()` function. This occurs because the function uses a loose comparison operator (`!=`) instead of a strict one (`!==`) when validating the `token` parameter against a secret string. Because the REST route `/wp-json/helpfulcrowd/v1/update-settings` is unauthenticated (using `__return_true` for its permission callback), an attacker can provide a JSON boolean `true` as the token. In PHP, `true` loosely matches any non-empty string, bypassing the check. This allows unauthenticated attackers to call `helpfulcrowd_settings_endpoint()` and inject arbitrary key-value pairs into the `helpfulcrowd_options` database table via `update_option()`.

Affected products

  • Helpfulcrowd Helpfulcrowd Product Reviews up to, and including, 1.2.9

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References