Authorization Bypass Vulnerability in Customer Reviews for WooCommerce Plugin
CVE-2026-89055

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 September 2026

What is CVE-2026-89055?

The Customer Reviews for WooCommerce plugin allows attackers to bypass authorization checks, facilitating the permanent deletion of arbitrary media library attachments. Unauthenticated users can exploit this vulnerability by injecting IDs of attachments into reviews submitted via publicly accessible forms. When these reviews are subsequently trashed and purged, products owned by administrators, including images and documents, can be permanently removed without proper authorization. The issue affects all versions of the plugin prior to 5.120.0 and arises from inadequate verification processes, posing significant risks to user content and data integrity.

Affected Version(s)

Customer Reviews for WooCommerce 0 <= 5.120.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HumbertoSP
.