← All CVEs NewScan detects
high

CVE-2026-89055

Customer Reviews for WooCommerce authorization bypass - a plugin endpoint does not check the caller's capability before acting

Severity
high
Affected product
customer-reviews-woocommerce
Affected versions
customer-reviews-woocommerce ≤ 5.120.0
Fixed in
customer-reviews-woocommerce a release above 5.120.0
Added to NewScan
2026-09-25
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints customer-reviews-woocommerce from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-25 (/daily-cve), CVSS 9.1. Appended to an EXISTING key rather than minting one, which is the whole reason this row is worth writing: the join is already proven by the 2026-08-30 row above - scan_wordpress reads the version from the plugin's own readme.txt under this exact slug - so the row is live the moment the pack ships instead of waiting on a fingerprint. `le` not `lt`: the advisory reads 'all versions up to, AND INCLUDING, 5.120.0', and the fixed release is not named, so the gate has to include 5.120.0 itself and fixed_in says so in words instead of inventing a number. Version-match only, like its sibling: confirming an authorization bypass means performing the privileged action on a live storefront.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →