CVE-2026-89055
Customer Reviews for WooCommerce authorization bypass - a plugin endpoint does not check the caller's capability before acting
- Severity
- high
- Affected product
- customer-reviews-woocommerce
- Affected versions
- customer-reviews-woocommerce ≤ 5.120.0
- Fixed in
- customer-reviews-woocommerce a release above 5.120.0
- Added to NewScan
- 2026-09-25
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints customer-reviews-woocommerce from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-25 (/daily-cve), CVSS 9.1. Appended to an EXISTING key rather than minting one, which is the whole reason this row is worth writing: the join is already proven by the 2026-08-30 row above - scan_wordpress reads the version from the plugin's own readme.txt under this exact slug - so the row is live the moment the pack ships instead of waiting on a fingerprint. `le` not `lt`: the advisory reads 'all versions up to, AND INCLUDING, 5.120.0', and the fixed release is not named, so the gate has to include 5.120.0 itself and fixed_in says so in words instead of inventing a number. Version-match only, like its sibling: confirming an authorization bypass means performing the privileged action on a live storefront.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →