Stored DOM-Based Cross-Site Scripting in Photo Reviews for WooCommerce Plugin
CVE-2026-100161
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-100161?
The Photo Reviews for WooCommerce plugin for WordPress is susceptible to an attack due to insufficient input sanitization and output escaping related to the 'wcpr_image_upload_id' parameter. This loophole allows unauthenticated attackers to inject arbitrary scripts into web pages viewed by users. Essentially, when a product review is posted, the poorly secured nonce 'wcpr_image_upload' could be exploited by any visitor, enabling them to store harmful payloads in comment metadata. Once a review containing the malicious script is displayed on the frontend, the injected code is executed, potentially compromising user data and site integrity.
Affected Version(s)
Photo Reviews for WooCommerce 0 <= 1.2.30