Skip to content
Threat Feed
high advisory

Stored XSS in Customer Reviews for WooCommerce Plugin

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization of the Comment Author Name, allowing unauthenticated attackers to execute arbitrary scripts.

CVE search metadata

CVE search record: CVE-2026-97663. Severity: high. CVSS: 7.2. KEV: no. Product: Customer Reviews for WooCommerce (<= 5.122.0). Brief: Stored XSS in Customer Reviews for WooCommerce Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-97663/

The Customer Reviews for WooCommerce plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-97663, impacting all versions up to and including 5.122.0. The vulnerability stems from inadequate sanitization of user-supplied data in the 'Comment Author Name' field. An unauthenticated attacker can exploit this when the plugin's image attachment functionality is active. By leveraging the 'wp_ajax_nopriv_cr_upload_local_images_frontend' endpoint alongside the 'ivole_attach_image' parameter, an attacker can submit a review containing an entity-encoded malicious script. When an unsuspecting user or administrator views a page where this review is displayed, the payload executes within their browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the victim, or the theft of sensitive session data. Organizations using this plugin should verify if the image attachment feature is enabled and ensure the plugin is updated to a patched version beyond 5.122.0 once available.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user viewing the affected WordPress page. This typically results in full account compromise if the victim is an administrator, enabling the attacker to modify site content, redirect users to malicious sites, or deploy further backdoors within the WordPress environment.

Recommendation

  • Audit the WordPress environment to confirm if the Customer Reviews for WooCommerce plugin is in use and identify if the image attachment feature is enabled.
  • Patch the plugin immediately upon the release of version 5.123.0 or later by the vendor.
  • Implement a Web Application Firewall (WAF) rule to inspect and block requests to the 'wp-admin/admin-ajax.php' endpoint where the query parameter 'action' is set to 'cr_upload_local_images_frontend' and the request body contains anomalous script-like payloads in the author name or attachment parameters.
  • Disable the image attachment feature for reviews if it is not a strictly required business function until the patch can be applied.

Immediate actions

Deploy the Sigma detection rule to monitor for exploitation attempts targeting the identified AJAX endpoint.

Detection Engineering 24h

Mitigations

Disable the image attachment feature (ivole_attach_image) in the plugin configuration until version 5.123.0 or later is available.

immediate IT Operations

CVE-2026-97663

Detection coverage 1

Detects CVE-2026-97663 Exploitation - XSS via wp_ajax_nopriv_cr_upload_local_images_frontend

high

Detects potential exploitation attempts of CVE-2026-97663 by monitoring for POST requests to the plugin's AJAX endpoint that contain common XSS vector signatures in associated parameters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →