WPHizmet

Eklenti güvenlik geçmişi

Customer Reviews for WooCommerce güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Customer Reviews for WooCommerce eklentisi için 27 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 12 tanesi kritik veya yüksek önemde, 14 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 5.124.0.

Toplam kayıt
27
Kritik veya yüksek
12
Oturumsuz istismar
14
Son kayıt
2 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-97663Yüksek · 7,22 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.122.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-96823Yüksek · 7,530 Eylül 2026

    eksik yetki denetimi

    Etkilenen sürümler: 5.120.0 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.

  • CVE-2026-89055Kritik · 9,125 Eylül 2026

    eksik yetki denetimi

    Etkilenen sürümler: 5.120.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product images, logos, and documents — by injecting their IDs into a review that is later trashed and purged. Exploitation requires a public review-form link (a 13-hex formId distributed to customers via e-mail), which exposes the nonce needed to reach the handler without any WordPress account or session.

  • CVE-2026-76585Yüksek · 8,830 Ağustos 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.118.0 öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

  • CVE-2026-6176Yüksek · 7,228 Ağustos 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.106.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review submissions from unauthenticated users through the 'cr_local_forms_submit' AJAX action without sanitizing HTML content before storing it via wp_insert_comment(), and later renders this stored content on product pages through comment_text() without proper escaping. This makes it possible for unauthenticated attackers with a valid review form URL (obtainable through review reminder emails sent to customers who placed orders) to inject arbitrary web scripts in pages that will execute whenever a user accesses the affected product page.

  • CVE-2026-14941Orta · 5,410 Ağustos 2026

    eksik yetki denetimi

    Etkilenen sürümler: 5.116.0 öncesi

    The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.

  • CVE-2026-12684Orta · 6,516 Temmuz 2026

    kısıtlamasız dosya yükleme

    Etkilenen sürümler: 5.113.0 öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist) to the Media Library and create attachment posts, leading to media library pollution and disk space exhaustion.

  • CVE-2026-13771Orta · 6,49 Temmuz 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.113.0 ve öncesi

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2026-56043Yüksek · 7,126 Haziran 2026

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.110.1 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

  • CVE-2026-3355Orta · 6,116 Nisan 2026

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.101.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

  • CVE-2026-4664Orta · 5,310 Nisan 2026

    kimlik doğrulama atlatma

    Etkilenen sürümler: 5.103.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict equality (`===`), without verifying that the stored key is non-empty. For orders where no review reminder email has been sent, the `ivole_secret_key` meta is not set, causing `get_meta()` to return an empty string. An attacker can supply `key: ""` to match this empty value and bypass the permission check. This makes it possible for unauthenticated attackers to submit, modify, and inject product reviews on any product — including products not associated with the referenced order — via the REST API endpoint `POST /ivole/v1/review`. Reviews are auto-approved by default since `ivole_enable_moderation` defaults to `"no"`.

  • CVE-2026-1316Yüksek · 7,212 Şubat 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.97.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests' is enabled) to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2025-14891Orta · 6,47 Ocak 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.93.1 ve öncesi

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. While it is possible to invoke the AJAX action without authentication, the attacker would need to know a valid form ID, which requires them to place an order. This vulnerability can be exploited by unauthenticated attackers if guest checkout is enabled. However, the form ID still needs to be obtained through placing an order.

  • CVE-2025-5720Orta · 6,431 Temmuz 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.80.2 ve öncesi

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2023-45101Orta · 4,32 Ocak 2025

    eksik yetki denetimi

    Etkilenen sürümler: 5.36.0 ve öncesi

    Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce customer-reviews-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through <= 5.36.0.

  • CVE-2024-10614Orta · 4,316 Kasım 2024

    eksik yetki denetimi

    Etkilenen sürümler: 5.61.0 ve öncesi

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import or check on the status.

  • CVE-2024-3731Orta · 6,119 Nisan 2024

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.47.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

  • CVE-2024-3869Orta · 4,316 Nisan 2024

    eksik yetki denetimi

    Etkilenen sürümler: Kayıtta belirtilmemiş

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.

  • CVE-2024-3243Orta · 4,316 Nisan 2024

    eksik yetki denetimi

    Etkilenen sürümler: 5.46.0 ve öncesi

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.

  • CVE-2024-1044Orta · 5,329 Şubat 2024

    eksik yetki denetimi

    Etkilenen sürümler: 5.38.12 ve öncesi · Oturum açmadan istismar edilebilir

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email addresses regardless of whether reviews are globally enabled.

  • CVE-2023-51692Orta · 4,328 Şubat 2024

    eksik yetki denetimi

    Etkilenen sürümler: 5.38.1 ve öncesi

    Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.

  • CVE-2023-0079Orta · 5,416 Ocak 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.17.0 öncesi

    The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

  • CVE-2023-6979Yüksek · 8,811 Ocak 2024

    kısıtlamasız dosya yükleme

    Etkilenen sürümler: 5.38.9 ve öncesi

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

  • CVE-2023-0080Yüksek · 8,813 Şubat 2023

    uzaktan kod çalıştırma

    Etkilenen sürümler: 5.16.0 öncesi

    The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.

  • CVE-2022-40194Yüksek · 7,523 Eylül 2022

    hassas bilgi ifşası

    Etkilenen sürümler: 5.3.5 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress

  • CVE-2022-38470Yüksek · 8,823 Eylül 2022

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 5.3.5 ve öncesi · Oturum açmadan istismar edilebilir

    Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.

  • CVE-2022-38134Yüksek · 8,823 Eylül 2022

    güvenlik

    Etkilenen sürümler: 5.3.5 ve öncesi

    Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.