VYPR

Helpfulcrowd Product Reviews

by WordPress

CVEs (1)

  • CVE-2026-8499MedJun 9, 2026
    risk 0.34cvss 5.3epss

    The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `helpfulcrowd_validate_token()` function using a loose comparison operator (`!=`) instead of a strict…