{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awp_photo_reviews_projectphoto_reviews_for_woocommercewordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp_photo_reviews_project:photo_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-101923"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Photo Reviews for WooCommerce (\u003c= 1.2.30)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Photo Reviews for WooCommerce plugin for WordPress, in versions 1.2.30 and below, contains a critical security flaw that allows for unauthorized content deletion. The vulnerability stems from the plugin's failure to validate the wcpr_image_upload_id parameter during public review submissions. An unauthenticated attacker can submit a review containing an arbitrary post ID, which the plugin stores in the review's comment metadata.\u003c/p\u003e\n\u003cp\u003eThe plugin's delete_reviews_image() handler later processes this metadata by calling wp_delete_post() on the stored IDs. Consequently, when an administrator deletes the malicious review, or when the wp_scheduled_delete cron job purges the comment trash, the system unknowingly deletes the site content corresponding to the injected IDs. This impact includes the permanent loss of products, posts, pages, and media attachments. The vulnerability was disclosed via the NVD, and users are advised to upgrade to a version that addresses the lack of ownership verification on submitted image metadata IDs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the permanent, unauthorized deletion of arbitrary site data, including essential WooCommerce product pages, blog posts, media attachments, and administrative pages. If widely exploited, this vulnerability could cause massive site data loss, significant service disruption, and potential financial impact for e-commerce operators relying on the affected WooCommerce installation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the \u0026quot;Photo Reviews for WooCommerce\u0026quot; plugin to the latest version (above 1.2.30) where verification of metadata IDs has been implemented.\u003c/li\u003e\n\u003cli\u003eReview database or system logs for suspicious review submissions containing unconventional or unexpected ID values in the wcpr_image_upload_id parameter.\u003c/li\u003e\n\u003cli\u003eDisable the \u0026quot;Photo Reviews for WooCommerce\u0026quot; plugin until a patch is applied if the site cannot be updated immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T06:53:48Z","date_published":"2026-10-03T06:53:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-photo-reviews-wc-vuln/","summary":"An unauthenticated arbitrary content deletion vulnerability in the Photo Reviews for WooCommerce plugin (CVE-2026-101923) allows attackers to delete arbitrary site posts, pages, or media by injecting malicious IDs into review metadata.","title":"Arbitrary Content Deletion in Photo Reviews for WooCommerce Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-photo-reviews-wc-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wp_photo_reviews_project:photo_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}