Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76585— Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Parameter

Quick assessment

Affected
Unknown Customer Reviews for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: WooCommerce 的客户评论(Customer Reviews)WordPress 插件在 5.11.8 之前的版本中,未对其端点接收到的客户评论内容进行净化(sanitize)和转义(escape),这使得未认证用户有可能执行存储型跨站脚本(Stored XSS)攻击。 --- 术语说明: Sanitise: 数据净化,指去除或替换数据中不安全或无效的部分。 Escape: 转义,通常指将 HTML 特殊字符转换为安全的表示形式,防止被解释为 HTML 标签。 Unauth

AI Predicted 6.1 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1059.001 · PowerShell
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76585

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Customer Reviews for WooCommerce 0 ~ 5.118.0 -

II. Public POCs for CVE-2026-76585

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76585

登录查看更多情报信息。

Other References for CVE-2026-76585 (1)

Same Patch Batch · Unknown · 2026-08-30 · 7 CVEs total

CVE-2026-81660 Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field
CVE-2026-81766 Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation vi
CVE-2026-78364 MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List
CVE-2026-19722 WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup
CVE-2026-14835 SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Pos
CVE-2026-14307 Geotargeting WP < 3.5.6.2 - Reflected XSS

IV. Related Vulnerabilities

V. Comments for CVE-2026-76585

No comments yet


Leave a comment