Sceawere
Vulnerability Detail
CVE-2026-100515UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Photo Reviews
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 2h ago
- Vendor
- VillaTheme
- Product
- Photo Reviews for WooCommerce
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-05T19:17:12.200Z",
"pubdate": "2026-10-05T19:17:12.200Z",
"executiveSummary": "VillaTheme Photo Reviews for WooCommerce, versions 1.2.30 and prior, contains a Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw stems from the improper neutralization of user-supplied input during web page generation. By injecting malicious scripts into the application, an unauthenticated attacker can execute arbitrary JavaScript in the context of an end-user's browser session. The primary impact involves the potential compromise of user accounts, theft of sensitive session cookies, and unauthorized manipulation of the website's appearance or functionality. As the vulnerability is reflected, it typically requires the victim to click a specially crafted malicious link, making it a social engineering-based vector. The risk to the site integrity and user privacy is significant, necessitating immediate attention to input sanitization and output encoding protocols within the affected plugin components.",
"technicalDetails": "The vulnerability is identified as a Reflected Cross-Site Scripting (XSS) flaw localized within the Photo Reviews for WooCommerce plugin. The root cause is the failure of the application to properly sanitize or validate input parameters before reflecting them within the HTTP response body. Because the plugin processes parameters from the request URI without sufficient character filtering or context-aware output encoding, an attacker can supply a malicious payload—typically containing HTML or JavaScript tags—that is subsequently rendered by the victim's web browser.\nThe attack flow begins when an attacker crafts a malicious URL containing a JavaScript payload embedded within a vulnerable query parameter. This URL is then distributed to targets through phishing campaigns or embedded within compromised links. When a victim interacts with the link while authenticated to the affected WooCommerce environment, the server processes the input and includes the unescaped script in the rendered HTML page. The browser, failing to distinguish between legitimate application code and the injected script, executes the malicious payload in the security context of the origin domain.\nThis execution occurs entirely within the client-side environment. Since the script runs within the session context of the authenticated victim, it gains access to the Document Object Model (DOM) of the page. The payload can be programmed to perform various post-exploitation actions, including stealing session tokens stored in local storage or cookies, redirecting users to malicious external domains, or performing actions on behalf of the user, such as administrative changes or unauthorized purchases within WooCommerce.\nThe vulnerability affects all versions of the plugin up to and including 1.2.30. Exploitation does not require prior authentication for the attacker, though the impact is maximized when the target is an authenticated administrator or a user with elevated privileges. The exposure is limited to the web application's frontend interface where the plugin processes user input, but the lack of server-side sanitization allows this client-side breach to occur. The lack of robust Content Security Policy (CSP) headers may further facilitate the execution of these malicious scripts, as the application fails to restrict the sources from which scripts are allowed to execute."
}