Stored DOM-Based Cross-Site Scripting in Photo Reviews for WooCommerce Plugin
CVE-2026-100161

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-100161?

The Photo Reviews for WooCommerce plugin for WordPress is susceptible to an attack due to insufficient input sanitization and output escaping related to the 'wcpr_image_upload_id' parameter. This loophole allows unauthenticated attackers to inject arbitrary scripts into web pages viewed by users. Essentially, when a product review is posted, the poorly secured nonce 'wcpr_image_upload' could be exploited by any visitor, enabling them to store harmful payloads in comment metadata. Once a review containing the malicious script is displayed on the frontend, the injected code is executed, potentially compromising user data and site integrity.

Affected Version(s)

Photo Reviews for WooCommerce 0 <= 1.2.30

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrien Brunner
.