Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Customer Reviews for WooCommerce — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Customer Reviews for WooCommerce, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerability aggregation data for the Customer Reviews for WooCommerce plugin, categorized by vendor and specific weakness types. It compiles known security flaws and advisories associated with this WordPress extension, covering incidents reported from early 2021 through the present. The content focuses on technical details rather than narrative summaries, providing a structured view of the security landscape surrounding this popular e-commerce tool. Visitors to this page can track a vendor's advisories to stay informed about ongoing remediation efforts and patch releases. You can also understand a weakness class by analyzing how specific coding errors, such as cross-site scripting or insecure direct object references, manifest within the plugin's codebase. Additionally, users can look up a product's vulnerability history to assess the overall security posture of the software over time. This historical perspective helps developers and site administrators evaluate the reliability of updates and prioritize security audits. By consolidating these disparate reports into a single view, the page aims to reduce the effort required to monitor a single plugin's security status. It serves as a reference for security professionals who need to verify if specific versions are affected by known issues or to understand the frequency and severity of past exploits. The data is organized to facilitate quick lookup and comparison across different versions and vulnerability categories, supporting informed decision-making for website maintenance and risk management strategies without relying on external notifications.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-14941 Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions --2026-08-10
CVE-2026-12684 Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media --2026-07-16
CVE-2026-13771 Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute CWE-79 6.4 Medium2026-07-09
CVE-2026-56043 WordPress Customer Reviews for WooCommerce plugin <= 5.110.1 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-06-26
CVE-2026-3355 Customer Reviews for WooCommerce <= 5.101.0 - Reflected Cross-Site Scripting via 'crsearch' CWE-79 6.1 Medium2026-04-16
CVE-2026-4664 Customer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' Parameter CWE-287 5.3 Medium2026-04-10
CVE-2026-1316 Customer Reviews for WooCommerce <= 5.97.0 - Unauthenticated Stored Cross-Site Scripting via media[].href Parameter CWE-79 7.2 High2026-02-12
CVE-2025-14891 Customer Reviews for WooCommerce <= 5.93.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName Parameter CWE-79 6.4 Medium2026-01-07
CVE-2025-5720 Customer Reviews for WooCommerce <= 5.80.2 - Unauthenticated Stored Cross-Site Scripting via `author` Parameter CWE-79 6.4 Medium2025-07-31
CVE-2023-45101 WordPress Customer Reviews for WooCommerce plugin <= 5.36.0 - Broken Access Control vulnerability CWE-862 4.3 Medium2025-01-02
CVE-2024-10614 Customer Reviews for WooCommerce <= 5.61.0 - Missing Authorization to Authenticated (Subscriber+) Import Cancellation CWE-862 4.3 Medium2024-11-16
CVE-2024-3731 Customer Reviews for WooCommerce <= 5.47.0 - Reflected Cross-Site Scripting via 's' CWE-79 6.1 Medium2024-04-19
CVE-2024-3243 Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending CWE-862 4.3 Medium2024-04-16
CVE-2024-3869 Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Coupon Search CWE-862 4.3 Medium2024-04-16
CVE-2023-51692 WordPress Customer Reviews for WooCommerce Plugin <= 5.38.1 is vulnerable to Broken Access Control CWE-862 4.3 Medium2024-02-28
CVE-2024-1044 Customer Reviews for WooCommerce <= 5.38.10 - Improper Authorization via submit_review CWE-284 5.3 Medium2024-02-20
CVE-2023-0079 Customer Reviews for WooCommerce < 5.17.0 - Contributor+ Stored XSS 5.4AIMediumAI2024-01-16
CVE-2023-6979 Customer Reviews for WooCommerce <= 5.38.9 - Authenticated (Author+) Arbitrary File Upload CWE-434 8.8 High2024-01-11
CVE-2023-0080 Customer Reviews for WooCommerce < 5.16.0 - Contributor+ LFI 8.8 -2023-02-13

All 19 known CVE vulnerabilities affecting Customer Reviews for WooCommerce with full Chinese analysis, references, and POCs where available.