Stored Cross-Site Scripting in Customer Reviews Plugin for WordPress
CVE-2026-6176

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 August 2026

What is CVE-2026-6176?

The Customer Reviews for WooCommerce plugin for WordPress allows Stored Cross-Site Scripting due to insufficient input sanitization of review comments. This vulnerability enables unauthenticated users to submit malicious scripts via the review submission form, which are then executed on the product pages when rendered. The flaw arises as the plugin fails to sanitize HTML content before it is stored and displayed, allowing potential exploitation when users access affected pages.

Affected Version(s)

Customer Reviews for WooCommerce 0 <= 5.106.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.