<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wordpress:photo_reviews_for_woocommerce:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awordpressphoto_reviews_for_woocommerce/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:52:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awordpressphoto_reviews_for_woocommerce/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored DOM-Based XSS in Photo Reviews for WooCommerce Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-photo-reviews-xss/</link><pubDate>Sat, 10 Oct 2026 07:52:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-photo-reviews-xss/</guid><description>The Photo Reviews for WooCommerce plugin for WordPress contains a Stored DOM-Based XSS vulnerability (CVE-2026-100161) allowing unauthenticated attackers to inject malicious scripts into product reviews.</description><content:encoded><![CDATA[<p>The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting (XSS) via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30. This vulnerability arises from insufficient input sanitization and output escaping. An unauthenticated attacker can exploit this flaw because the plugin fails to perform necessary capability or ownership checks when processing the 'wcpr_image_upload' nonce. The malicious payload is stored within comment metadata, which is not subjected to 'wp_kses' filtering. Consequently, the injected JavaScript executes in the browser of any user viewing the affected product review page on the frontend. This vulnerability poses a significant risk for session hijacking, unauthorized actions, and credential theft, particularly if administrative users view the compromised content.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users' sessions. This can lead to the theft of session cookies, unauthorized modification of website content, or the execution of malicious actions on behalf of administrators or customers, significantly impacting the integrity and security of the affected WordPress site.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Photo Reviews for WooCommerce plugin to the latest available version (beyond 1.2.30) where the input sanitization and nonce verification have been patched. Security teams should scan the WordPress database for anomalous JavaScript patterns injected into wp_comments or associated comment metadata.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>