← All CVEs NewScan detects
medium

CVE-2026-76585

Customer Reviews for WooCommerce stored cross-site scripting - review content from one of its endpoints is neither sanitised nor escaped

Severity
medium
Affected product
customer-reviews-woocommerce
Affected versions
customer-reviews-woocommerce < 5.118.0
Fixed in
customer-reviews-woocommerce 5.118.0
Added to NewScan
2026-08-30
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints customer-reviews-woocommerce from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-30 (/daily-cve). Same generic slug->readme.txt version source; slug verified against api.wordpress.org ('Customer Reviews for WooCommerce', current 5.119.0). Reviews are submitted by unauthenticated shoppers and rendered on the product page, so the payload lands in front of every visitor. Version-match only: the confirming action would publish a script payload on a live storefront.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →