Sceawere

Vulnerability Detail

CVE-2026-100161UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Photo Reviews Stored DOM XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
villatheme
Product
Photo Reviews for WooCommerce
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The publicly-emitted `wcpr_image_upload` nonce printed on every product review form is the only gate, and no capability, authentication, or attachment ownership check is performed, allowing the payload to be stored in comment meta — which is not subject to `wp_kses` — by any unauthenticated visitor; the XSS fires once the review is visible on the frontend.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-10T07:16:38.767Z",
  "pubdate": "2026-10-10T07:16:38.767Z",
  "executiveSummary": "The Photo Reviews for WooCommerce plugin for WordPress is susceptible to a Stored DOM-based Cross-Site Scripting (XSS) vulnerability. The flaw exists in versions up to and including 1.2.30.\nThe vulnerability arises from improper input sanitization and output escaping within the 'wcpr_image_upload_id' parameter. An unauthenticated attacker can inject arbitrary malicious JavaScript payloads that are stored within comment meta data.\nBecause the plugin fails to implement mandatory capability checks, authentication requirements, or attachment ownership verification, any remote, unauthenticated attacker can exploit this weakness. The injected script executes in the browser of any user who views the affected product review page.\nThis vulnerability poses a high risk to site integrity and user security, as it allows attackers to hijack user sessions, perform unauthorized actions on behalf of site administrators, or redirect users to malicious domains. The exploitation is facilitated by the public exposure of the 'wcpr_image_upload' nonce, which is present on all product review forms, lowering the barrier for entry for potential exploiters.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the Photo Reviews for WooCommerce plugin to validate and sanitize user-supplied input provided to the 'wcpr_image_upload_id' parameter before it is processed by the application's backend. The plugin architecture stores this parameter directly into comment meta fields.\nA critical security oversight is that data stored within these comment meta fields is not subjected to 'wp_kses' filtering or similar output sanitization routines typically applied to user-generated content in WordPress. Consequently, malicious payloads injected into this field are persisted in the database without modification.\nThe attack flow commences when an unauthenticated actor identifies a product page containing the Photo Reviews for WooCommerce review form. The attacker retrieves the publicly-emitted 'wcpr_image_upload' nonce, which is exposed in the HTML source code. Leveraging this nonce, the attacker constructs an HTTP request that includes the malicious JavaScript payload within the 'wcpr_image_upload_id' parameter.\nBecause the application does not enforce authentication or verify user permissions—such as checking for 'manage_options' or verifying if the user is the owner of the comment/attachment—the request is accepted by the server. The payload is successfully written to the database.\nThe DOM-based XSS executes when the browser renders the review section on the frontend of the WooCommerce store. When a victim loads the page, the application retrieves the stored meta data and injects the malicious script into the Document Object Model (DOM). The script executes within the context of the user's browser session.\nThe impact of this execution is broad. Attackers may perform actions such as extracting session cookies, capturing keystrokes, performing unauthorized administrative operations via XHR/Fetch requests, or altering the visual integrity of the site to conduct phishing campaigns. Because the plugin processes the 'wcpr_image_upload_id' without contextual encoding for the frontend, the execution occurs automatically for any visitor, including high-privileged users like administrators, leading to potential full site compromise."
}
CVE-2026-100161: Photo Reviews Stored DOM XSS (HIGH Severity, CVSS: 7.2) | Sceawere