Authorization Bypass Vulnerability in Customer Reviews for WooCommerce Plugin
CVE-2026-89055
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-89055?
The Customer Reviews for WooCommerce plugin allows attackers to bypass authorization checks, facilitating the permanent deletion of arbitrary media library attachments. Unauthenticated users can exploit this vulnerability by injecting IDs of attachments into reviews submitted via publicly accessible forms. When these reviews are subsequently trashed and purged, products owned by administrators, including images and documents, can be permanently removed without proper authorization. The issue affects all versions of the plugin prior to 5.120.0 and arises from inadequate verification processes, posing significant risks to user content and data integrity.
Affected Version(s)
Customer Reviews for WooCommerce 0 <= 5.120.0