VYPR

Customer Reviews For Woocommerce

by WordPress

Source repositories

CVEs (25)

  • CVE-2024-3243MedApr 16, 2024
    risk 0.21cvss 4.3epss 0.00

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with…

  • CVE-2026-14942Aug 28, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. The report was withdrawn: the precondition it depends on, an attacker obtaining a review form identifier belonging to a…

  • CVE-2026-12684MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.00

    The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files…

  • CVE-2026-13771MedJul 9, 2026
    risk 0.00cvss 6.4epss 0.00

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-56043HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

Page 2 of 2