Sceawere

Vulnerability Detail

CVE-2026-97663UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Customer Reviews

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
15h ago
Vendor
ivole
Product
Customer Reviews for WooCommerce
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T08:17:06.000Z",
  "pubdate": "2026-10-02T08:17:06.000Z",
  "executiveSummary": "The Customer Reviews for WooCommerce plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing in the comment author name field.\nThe vulnerability exists in all versions up to, and including, 5.122.0.\nAn unauthenticated attacker can exploit this flaw to inject arbitrary JavaScript, which will execute in the browser context of any user viewing the compromised page, including administrative users.\nThe exploitation is contingent upon the activation of the 'ivole_attach_image' feature.\nThis vulnerability stems from a failure to perform adequate input sanitization and output escaping on user-supplied data during the review submission process.\nThe attack is facilitated by the publicly exposed 'wp_ajax_nopriv_cr_upload_local_images_frontend' endpoint.\nSuccessful exploitation allows for session hijacking, unauthorized actions performed on behalf of authenticated users, and defacement of the affected WordPress site.\nGiven the ability for unauthenticated exploitation, this represents a significant security risk requiring immediate attention.",
  "technicalDetails": "The root cause of this vulnerability is improper sanitization of the 'comment_author' field during the submission of a WooCommerce review. The plugin fails to validate or encode the author name before storing it in the database and subsequently rendering it in the frontend or backend interface.\nThe vulnerability is reachable when the 'ivole_attach_image' feature is enabled, which facilitates the handling of image attachments via the AJAX endpoint 'wp_ajax_nopriv_cr_upload_local_images_frontend'.\nAn unauthenticated attacker can trigger this vulnerability by crafting a malicious review submission. The attack flow begins with the attacker interacting with the review submission form. By providing a specially crafted payload—such as an entity-encoded script tag—within the author name field, the attacker bypasses surface-level input checks.\nThe server-side code handling the 'wp_ajax_nopriv_cr_upload_local_images_frontend' request processes the submitted review data. Because the plugin does not properly sanitize or escape the input before database persistence, the malicious script is stored as part of the comment metadata.\nWhen a user (guest or administrator) visits a page where the review is displayed, the server renders the stored author name directly into the HTML document. The browser interprets the injected payload as executable JavaScript, leading to the execution of arbitrary commands in the victim's session context.\nSince the attack executes in the victim's browser, the attacker can leverage this for various post-exploitation activities. This includes stealing sensitive session cookies, performing unauthorized operations via forged HTTP requests (CSRF), redirecting users to malicious domains, or deploying further XSS-based payloads to escalate privileges or exfiltrate sensitive site data.\nThe exposure is widespread due to the 'wp_ajax_nopriv_cr_upload_local_images_frontend' endpoint being explicitly designed for unauthenticated access, requiring no authentication or privilege tokens for the initial interaction. Consequently, the attack surface is exposed to any network-capable actor with access to the public-facing WordPress site.\nAffected versions are strictly those up to and including 5.122.0. The vulnerability is entirely stored-based, meaning that once the payload is injected, it remains persistent until manually removed from the database or the vulnerable code is patched to enforce strict output encoding."
}
CVE-2026-97663: Stored XSS in Customer Reviews (HIGH Severity, CVSS: 7.2) | Sceawere