Vulnerability in Customer Reviews for WooCommerce — CVE-2026-76585
HighSeverity
0.3%Estimated exploit probability
80,000+ sitesInstalls
5.118.0Fixed in
What to do now
Update Customer Reviews for WooCommerce to 5.118.0 or later.
Affected versions
- Everything before 5.118.0
Affected: Customer Reviews for WooCommerce (plugin, customer-reviews-woocommerce)
What the vulnerability is
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 5.118.0. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.