VYPR

Customer Reviews For Woocommerce

by WordPress

Source repositories

CVEs (22)

  • CVE-2026-13771MedJul 9, 2026
    risk 0.00cvss 6.4epss 0.00

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-56043HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

Page 2 of 2