Sceawere
Vulnerability Detail
CVE-2026-96823UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WooCommerce Reviews Content Deletion
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- CusRev
- Product
- Customer Reviews for WooCommerce
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T13:17:31.917Z",
"pubdate": "2026-09-30T13:17:31.917Z",
"executiveSummary": "The Customer Reviews for WooCommerce plugin for WordPress, in versions up to and including 5.120.0, is affected by a critical vulnerability categorized as unauthenticated arbitrary content deletion. This security flaw enables remote, unauthenticated attackers to delete arbitrary content, such as customer reviews, ratings, or associated metadata, from the target website.\nBecause the exploitation of this vulnerability requires zero administrative privileges and can be executed without user interaction, it poses a severe threat to the integrity and reliability of e-commerce platforms using the affected plugin. An attacker can systematically target and remove critical customer feedback, directly undermining the site's reputation, search engine optimization (SEO) rankings, and overall consumer trust.\nThe underlying issue lies in the application's failure to enforce proper access control and authorization checks on endpoints managing content deletion operations. Consequently, any web-facing entity can send maliciously crafted requests to delete valuable database entries. Organizations running WooCommerce with this plugin must immediately address this vulnerability to prevent unauthorized data loss and potential disruption of business operations.",
"technicalDetails": "This vulnerability exists within the 'Customer Reviews for WooCommerce' plugin (versions <= 5.120.0) due to a fundamental breakdown in access control implementation. Specifically, the plugin registers server-side handlers—typically via WordPress AJAX actions (wp_ajax_nopriv_*) or the WordPress REST API—designed to manage or delete user-submitted reviews and associated assets.\nIn a secure implementation, any endpoint capable of performing destructive database operations, such as deleting content, must perform strict authorization checks (e.g., verifying capabilities via current_user_can()) and validate a cryptographic handshake (e.g., verifying a nonce via wp_verify_nonce()). In the vulnerable versions of the plugin, these crucial security controls are absent or improperly implemented on the deletion routines.\nThe attack flow unfolds through a sequence of step-by-step actions. First, an attacker scans or identifies a WordPress instance running the Customer Reviews for WooCommerce plugin at a version equal to or prior to 5.120.0. Second, the attacker maps the specific endpoint or registered AJAX action responsible for processing review deletions. Third, the attacker constructs an unauthenticated HTTP request (frequently a POST or GET request) targeted at the identified endpoint, including parameters that specify the target object's identifier, such as a post ID or review ID. Fourth, the attacker transmits the payload to the server. Because the plugin does not validate whether the requesting session possesses administrator or moderator privileges, the backend logic accepts the request as legitimate. Finally, the database query is executed, resulting in the permanent removal or corruption of the targeted review content or associated metadata.\nTo expand further, the vulnerability's root cause is rooted in Insecure Direct Object References (IDOR) coupled with missing function-level access control. When the server processes the deletion command, it relies solely on user-supplied parameters to identify which content to delete, without validating if the current session owner has the authority to delete that specific resource. This allows an attacker to perform parameter tampering, iterating through sequential IDs to systematically wipe out entire tables of reviews and associated metadata. The absence of robust token validation means that the endpoint is completely exposed to external automated scanning tools and simple curl-based exploit scripts, leading to rapid, automated database clearing."
}