Reflected Cross-Site Scripting Vulnerability in WP Customer Reviews Plugin
CVE-2026-11608

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 September 2026

What is CVE-2026-11608?

The WP Customer Reviews plugin for WordPress contains a vulnerability that can be exploited through the 'wpcr3_fname' parameter. Due to inadequate input sanitization and output escaping, this flaw allows unauthorized attackers to inject malicious web scripts into pages. If users are tricked into engaging with harmful content, such as clicking on a compromised link, they may execute arbitrary scripts, posing a significant security risk.

Affected Version(s)

WP Customer Reviews 0 <= 3.7.8

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Quang
.