Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-76585: WooCommerce Customer Reviews plugin can let attackers inject code

CVE-2026-76585 · published 4 days ago
Summary

The Customer Reviews add‑on for WooCommerce (versions before 5.118.0) does not properly clean the text that users submit in reviews. This means a stranger could place hidden scripts in a review that run for anyone who views it, potentially stealing data or altering the site. Update the plugin to the latest version or remove it until it is patched.

What to do
  • Update unknown customer reviews for woocommerce to version 5.118.0 or later.
Affected software
VendorProductAffected versions
unknown customer reviews for woocommerce < 5.118.0
Original advisory text
Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Parameter
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
References
Severity
8.8 High
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Sources
CVE-2026-76585 · MITRE
Monitor software like this
Free during beta