Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101923— Photo Reviews for WooCommerce <= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter

Quick assessment

Affected
villatheme Photo Reviews for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Photo Reviews for WooCommerce 插件在 1.2.30 及更早版本中存在任意内容删除漏洞。该漏洞源于:插件在公开评论提交过程中,从 参数中获取攻击者可控制的帖子 ID,并将其存入评论元数据( )中,但未验证这些 ID 是否属于提交者所拥有的附件;此外,在删除评论时, 处理函数会对每个存储的 ID 无条件调用 。因此,未认证的攻击者可以导致网站上任意的帖子、页面、产品或媒体附件被永久删除,只要管理员随后删除该攻击者提交的评论,或 WordPress 内置的 定时任务在

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101923

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Photo Reviews for WooCommerce <= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker's review (or when WordPress's built-in wp_scheduled_delete cron empties the comment trash after 30 days).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
villatheme Photo Reviews for WooCommerce 0 ~ 1.2.30 -

II. Public POCs for CVE-2026-101923

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101923

请登录查看更多情报信息。

Other References for CVE-2026-101923 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-101923

No comments yet


Leave a comment