Stored Cross-Site Scripting in Customer Reviews Plugin for WordPress
CVE-2026-6176
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-6176?
The Customer Reviews for WooCommerce plugin for WordPress allows Stored Cross-Site Scripting due to insufficient input sanitization of review comments. This vulnerability enables unauthenticated users to submit malicious scripts via the review submission form, which are then executed on the product pages when rendered. The flaw arises as the plugin fails to sanitize HTML content before it is stored and displayed, allowing potential exploitation when users access affected pages.
Affected Version(s)
Customer Reviews for WooCommerce 0 <= 5.106.0