CVE-2026-3355
Customer Reviews for WooCommerce
Minimum safe version
5.104.0
Update to 5.104.0 or later to address 24 fixable vulnerabilities
Customer Reviews for WooCommerce <= 5.97.0 - Unauthenticated Stored Cross-Site Scripting via media[].href Parameter
Customer Reviews for WooCommerce <= 5.103.0 - Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' Parameter
CVE-2025-14891
Customer Reviews for WooCommerce <= 5.80.2 - Unauthenticated Stored Cross-Site Scripting via `author` Parameter
WordPress Customer Reviews for WooCommerce Plugin <= 5.61.0 is vulnerable to Broken Access Control
Customer Reviews for WooCommerce < 5.38.2 - Missing Authorization via manual review reminders
Customer Reviews for WooCommerce < 5.38.2 - Cross-Site Request Forgery via manual review reminders
CVE-2024-3731
CVE-2024-3243
WordPress Customer Reviews for WooCommerce Plugin <= 5.46.0 is vulnerable to Broken Access Control
CVE-2024-1044
CVE-2023-6979
Customer Reviews for WooCommerce < 5.36.1 - Missing Authorization
WordPress Customer Reviews for WooCommerce Plugin <= 5.38.1 is vulnerable to Broken Access Control
Customer Reviews for WooCommerce <= 5.38.1 - Cross-Site Request Forgery via manual review reminders
Customer Reviews for WooCommerce <= 5.38.1 - Missing Authorization via manual review reminders
CVE-2023-45101
Customer Reviews for WooCommerce <= 5.36.0 - Missing Authorization
CVE-2023-0079
CVE-2023-0080
CVE-2022-38134
CVE-2022-38470
CVE-2022-40194