Insecure Direct Object References in WooCommerce Photo Reviews Plugin
CVE-2026-100517
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-100517?
The WooCommerce Photo Reviews plugin versions up to 1.2.30 are vulnerable to unauthenticated Insecure Direct Object References (IDOR). This vulnerability allows unauthorized users to access and manipulate resources that should be restricted. Attackers could exploit this weakness to view or modify sensitive data that is not supposed to be accessible to them, potentially compromising the integrity of the website. Website administrators are urged to update to the latest version of the plugin to mitigate this risk.
Affected Version(s)
Photo Reviews for WooCommerce <= 1.2.30