Sceawere
Vulnerability Detail
CVE-2026-97663UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Customer Reviews
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 15h ago
- Vendor
- ivole
- Product
- Customer Reviews for WooCommerce
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T08:17:06.000Z",
"pubdate": "2026-10-02T08:17:06.000Z",
"executiveSummary": "The Customer Reviews for WooCommerce plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing in the comment author name field.\nThe vulnerability exists in all versions up to, and including, 5.122.0.\nAn unauthenticated attacker can exploit this flaw to inject arbitrary JavaScript, which will execute in the browser context of any user viewing the compromised page, including administrative users.\nThe exploitation is contingent upon the activation of the 'ivole_attach_image' feature.\nThis vulnerability stems from a failure to perform adequate input sanitization and output escaping on user-supplied data during the review submission process.\nThe attack is facilitated by the publicly exposed 'wp_ajax_nopriv_cr_upload_local_images_frontend' endpoint.\nSuccessful exploitation allows for session hijacking, unauthorized actions performed on behalf of authenticated users, and defacement of the affected WordPress site.\nGiven the ability for unauthenticated exploitation, this represents a significant security risk requiring immediate attention.",
"technicalDetails": "The root cause of this vulnerability is improper sanitization of the 'comment_author' field during the submission of a WooCommerce review. The plugin fails to validate or encode the author name before storing it in the database and subsequently rendering it in the frontend or backend interface.\nThe vulnerability is reachable when the 'ivole_attach_image' feature is enabled, which facilitates the handling of image attachments via the AJAX endpoint 'wp_ajax_nopriv_cr_upload_local_images_frontend'.\nAn unauthenticated attacker can trigger this vulnerability by crafting a malicious review submission. The attack flow begins with the attacker interacting with the review submission form. By providing a specially crafted payload—such as an entity-encoded script tag—within the author name field, the attacker bypasses surface-level input checks.\nThe server-side code handling the 'wp_ajax_nopriv_cr_upload_local_images_frontend' request processes the submitted review data. Because the plugin does not properly sanitize or escape the input before database persistence, the malicious script is stored as part of the comment metadata.\nWhen a user (guest or administrator) visits a page where the review is displayed, the server renders the stored author name directly into the HTML document. The browser interprets the injected payload as executable JavaScript, leading to the execution of arbitrary commands in the victim's session context.\nSince the attack executes in the victim's browser, the attacker can leverage this for various post-exploitation activities. This includes stealing sensitive session cookies, performing unauthorized operations via forged HTTP requests (CSRF), redirecting users to malicious domains, or deploying further XSS-based payloads to escalate privileges or exfiltrate sensitive site data.\nThe exposure is widespread due to the 'wp_ajax_nopriv_cr_upload_local_images_frontend' endpoint being explicitly designed for unauthenticated access, requiring no authentication or privilege tokens for the initial interaction. Consequently, the attack surface is exposed to any network-capable actor with access to the public-facing WordPress site.\nAffected versions are strictly those up to and including 5.122.0. The vulnerability is entirely stored-based, meaning that once the payload is injected, it remains persistent until manually removed from the database or the vulnerable code is patched to enforce strict output encoding."
}