Cusrev
Cusrev Customer Reviews FOR Woocommerce: vulnerabilidades y CVE
Cusrev Customer Reviews FOR Woocommerce tiene 26 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses12
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96823 | Alta (7.5) | 0.43% | — | 30 sept 2026 | Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. |
| CVE-2026-89055 | Crítica (9.1) | 0.39% | — | 25 sept 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized… |
| CVE-2026-76585 | Alta (8.8) | 0.51% | — | 30 ago 2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform… |
| CVE-2026-6176 | Alta (7.2) | 0.42% | — | 28 ago 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input… |
| CVE-2026-14941 | Media (5.4) | 0.23% | — | 10 ago 2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to… |
| CVE-2026-12684 | Media (6.5) | 0.43% | — | 16 jul 2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is… |
| CVE-2026-13771 | Media (6.4) | 0.42% | — | 9 jul 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization… |
| CVE-2026-56043 | Alta (7.1) | 0.25% | — | 26 jun 2026 | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. |
| CVE-2026-3355 | Media (6.1) | 0.29% | — | 16 abr 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization… |
| CVE-2026-4664 | Media (5.3) | 0.57% | — | 10 abr 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing… |
| CVE-2026-1316 | Alta (7.2) | 0.27% | — | 12 feb 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization… |
| CVE-2025-14891 | Media (6.4) | 0.27% | — | 7 ene 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization… |
| CVE-2025-5720 | Media (6.4) | 0.30% | — | 31 jul 2025 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and… |
| CVE-2023-45101 | Media (4.3) | 0.33% | — | 2 ene 2025 | Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce customer-reviews-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for… |
| CVE-2024-10614 | Media (4.3) | 0.28% | — | 16 nov 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes… |
| CVE-2024-3731 | Media (6.1) | 0.37% | — | 19 abr 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and… |
| CVE-2024-3869 | Media (4.3) | 0.45% | — | 16 abr 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for… |
| CVE-2024-3243 | Media (4.3) | 0.43% | — | 16 abr 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0.… |
| CVE-2024-1044 | Media (5.3) | 0.41% | — | 29 feb 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including,… |
| CVE-2023-51692 | Media (4.3) | 0.34% | — | 28 feb 2024 | Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1. |
| CVE-2023-0079 | Media (5.4) | 0.53% | — | 16 ene 2024 | The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could… |
| CVE-2023-6979 | Alta (8.8) | 1.1% | — | 11 ene 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including,… |
| CVE-2023-0080 | Alta (8.8) | 1.1% | — | 13 feb 2023 | The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal… |
| CVE-2022-40194 | Alta (7.5) | 0.91% | — | 23 sept 2022 | Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress |
| CVE-2022-38470 | Alta (8.8) | 0.38% | — | 23 sept 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. |
| CVE-2022-38134 | Alta (8.8) | 1.0% | — | 23 sept 2022 | Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. |