CVE-2026-76585
N/A
N/A
Summary
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Customer Reviews for WooCommerce | 0 < 5.118.0 | affected |
Weaknesses
- CWE-79 Cross-Site Scripting (XSS)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.