The Customer Reviews for WooCommerce WordPress plugin...
High severity
Unreviewed
Published
Aug 30, 2026
to the GitHub Advisory Database
•
Updated Aug 31, 2026
Description
Published by the National Vulnerability Database
Aug 30, 2026
Published to the GitHub Advisory Database
Aug 30, 2026
Last updated
Aug 31, 2026
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
References