Stored XSS in Customer Reviews for WooCommerce Plugin
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization of the Comment Author Name, allowing unauthenticated attackers to execute arbitrary scripts.
CVE search metadata
CVE search record: CVE-2026-97663. Severity: high. CVSS: 7.2. KEV: no. Product: Customer Reviews for WooCommerce (<= 5.122.0). Brief: Stored XSS in Customer Reviews for WooCommerce Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-97663/
The Customer Reviews for WooCommerce plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-97663, impacting all versions up to and including 5.122.0. The vulnerability stems from inadequate sanitization of user-supplied data in the 'Comment Author Name' field. An unauthenticated attacker can exploit this when the plugin's image attachment functionality is active. By leveraging the 'wp_ajax_nopriv_cr_upload_local_images_frontend' endpoint alongside the 'ivole_attach_image' parameter, an attacker can submit a review containing an entity-encoded malicious script. When an unsuspecting user or administrator views a page where this review is displayed, the payload executes within their browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the victim, or the theft of sensitive session data. Organizations using this plugin should verify if the image attachment feature is enabled and ensure the plugin is updated to a patched version beyond 5.122.0 once available.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user viewing the affected WordPress page. This typically results in full account compromise if the victim is an administrator, enabling the attacker to modify site content, redirect users to malicious sites, or deploy further backdoors within the WordPress environment.
Recommendation
- Audit the WordPress environment to confirm if the Customer Reviews for WooCommerce plugin is in use and identify if the image attachment feature is enabled.
- Patch the plugin immediately upon the release of version 5.123.0 or later by the vendor.
- Implement a Web Application Firewall (WAF) rule to inspect and block requests to the 'wp-admin/admin-ajax.php' endpoint where the query parameter 'action' is set to 'cr_upload_local_images_frontend' and the request body contains anomalous script-like payloads in the author name or attachment parameters.
- Disable the image attachment feature for reviews if it is not a strictly required business function until the patch can be applied.
Immediate actions
Deploy the Sigma detection rule to monitor for exploitation attempts targeting the identified AJAX endpoint.
Mitigations
Disable the image attachment feature (ivole_attach_image) in the plugin configuration until version 5.123.0 or later is available.
CVE-2026-97663
Detection coverage 1
Detects CVE-2026-97663 Exploitation - XSS via wp_ajax_nopriv_cr_upload_local_images_frontend
highDetects potential exploitation attempts of CVE-2026-97663 by monitoring for POST requests to the plugin's AJAX endpoint that contain common XSS vector signatures in associated parameters.
Detection queries are available on the platform. Get full rules →