Skip to content
Threat Feed
high advisory

Stored DOM-Based XSS in Photo Reviews for WooCommerce Plugin

The Photo Reviews for WooCommerce plugin for WordPress contains a Stored DOM-Based XSS vulnerability (CVE-2026-100161) allowing unauthenticated attackers to inject malicious scripts into product reviews.

CVE search metadata

CVE search record: CVE-2026-100161. Severity: high. CVSS: 7.2. KEV: no. Product: Photo Reviews for WooCommerce (<= 1.2.30). Brief: Stored DOM-Based XSS in Photo Reviews for WooCommerce Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-photo-reviews-xss/

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting (XSS) via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30. This vulnerability arises from insufficient input sanitization and output escaping. An unauthenticated attacker can exploit this flaw because the plugin fails to perform necessary capability or ownership checks when processing the 'wcpr_image_upload' nonce. The malicious payload is stored within comment metadata, which is not subjected to 'wp_kses' filtering. Consequently, the injected JavaScript executes in the browser of any user viewing the affected product review page on the frontend. This vulnerability poses a significant risk for session hijacking, unauthorized actions, and credential theft, particularly if administrative users view the compromised content.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users' sessions. This can lead to the theft of session cookies, unauthorized modification of website content, or the execution of malicious actions on behalf of administrators or customers, significantly impacting the integrity and security of the affected WordPress site.

Recommendation

Update the Photo Reviews for WooCommerce plugin to the latest available version (beyond 1.2.30) where the input sanitization and nonce verification have been patched. Security teams should scan the WordPress database for anomalous JavaScript patterns injected into wp_comments or associated comment metadata.

Mitigations

Upgrade Photo Reviews for WooCommerce plugin to a version patched against CVE-2026-100161

immediate IT Operations

CVE-2026-100161