Skip to content
Threat Feed
high advisory

Arbitrary Content Deletion in Photo Reviews for WooCommerce Plugin

An unauthenticated arbitrary content deletion vulnerability in the Photo Reviews for WooCommerce plugin (CVE-2026-101923) allows attackers to delete arbitrary site posts, pages, or media by injecting malicious IDs into review metadata.

CVE search metadata

CVE search record: CVE-2026-101923. Severity: high. CVSS: 8.1. KEV: no. Product: Photo Reviews for WooCommerce (<= 1.2.30). Brief: Arbitrary Content Deletion in Photo Reviews for WooCommerce Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-photo-reviews-wc-vuln/

The Photo Reviews for WooCommerce plugin for WordPress, in versions 1.2.30 and below, contains a critical security flaw that allows for unauthorized content deletion. The vulnerability stems from the plugin's failure to validate the wcpr_image_upload_id parameter during public review submissions. An unauthenticated attacker can submit a review containing an arbitrary post ID, which the plugin stores in the review's comment metadata.

The plugin's delete_reviews_image() handler later processes this metadata by calling wp_delete_post() on the stored IDs. Consequently, when an administrator deletes the malicious review, or when the wp_scheduled_delete cron job purges the comment trash, the system unknowingly deletes the site content corresponding to the injected IDs. This impact includes the permanent loss of products, posts, pages, and media attachments. The vulnerability was disclosed via the NVD, and users are advised to upgrade to a version that addresses the lack of ownership verification on submitted image metadata IDs.

Impact

Successful exploitation leads to the permanent, unauthorized deletion of arbitrary site data, including essential WooCommerce product pages, blog posts, media attachments, and administrative pages. If widely exploited, this vulnerability could cause massive site data loss, significant service disruption, and potential financial impact for e-commerce operators relying on the affected WooCommerce installation.

Recommendation

Prioritized actions for administrators:

  • Immediately update the "Photo Reviews for WooCommerce" plugin to the latest version (above 1.2.30) where verification of metadata IDs has been implemented.
  • Review database or system logs for suspicious review submissions containing unconventional or unexpected ID values in the wcpr_image_upload_id parameter.
  • Disable the "Photo Reviews for WooCommerce" plugin until a patch is applied if the site cannot be updated immediately.

Immediate actions

Upgrade Photo Reviews for WooCommerce to a version beyond 1.2.30

IT Operations 24h

Mitigations

Upgrade plugin to latest patched version

immediate IT Operations

CVE-2026-101923