CVE-2026-76585
Customer Reviews for WooCommerce stored cross-site scripting - review content from one of its endpoints is neither sanitised nor escaped
- Severity
- medium
- Affected product
- customer-reviews-woocommerce
- Affected versions
- customer-reviews-woocommerce < 5.118.0
- Fixed in
- customer-reviews-woocommerce 5.118.0
- Added to NewScan
- 2026-08-30
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints customer-reviews-woocommerce from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-30 (/daily-cve). Same generic slug->readme.txt version source; slug verified against api.wordpress.org ('Customer Reviews for WooCommerce', current 5.119.0). Reviews are submitted by unauthenticated shoppers and rendered on the product page, so the payload lands in front of every visitor. Version-match only: the confirming action would publish a script payload on a live storefront.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →