{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/customer-reviews-for-woocommerce--5.120.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:woocommerce:customer_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-89055"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Customer Reviews for WooCommerce (\u003c= 5.120.0)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin","vulnerability","cve-2026-89055"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Customer Reviews for WooCommerce plugin for WordPress, in all versions up to and including 5.120.0, contains an authorization bypass vulnerability (CVE-2026-89055). The flaw originates from the plugin's failure to properly verify user permissions within a specific handler. This security oversight allows unauthenticated attackers to permanently delete arbitrary files, including sensitive administrative assets like product logos, documents, and images stored in the WordPress Media Library. The vulnerability is accessible through publicly shared review-form links, which contain a 13-hexadecimal formId and the necessary nonce to trigger the handler without requiring a valid WordPress session or user account. An attacker can leverage this by injecting attachment IDs into a review process that, when trashed and purged, results in the deletion of those specific items. Given the potential for destructive impact on site content and administrative configuration, this vulnerability represents a significant risk to site integrity.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized, permanent deletion of files from the WordPress Media Library. This can lead to site defacement, loss of critical business documentation, and disruption of e-commerce storefronts by removing product images. If widely targeted, this vulnerability could impact numerous WordPress instances utilizing this specific WooCommerce extension.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the Customer Reviews for WooCommerce plugin to the latest version (above 5.120.0) to address the authorization bypass.\u003c/li\u003e\n\u003cli\u003eAudit WordPress Media Library logs or integrity checkers if site tampering is suspected.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests to review-form handlers that do not correspond to legitimate customer interaction patterns.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-25T10:51:52Z","date_published":"2026-09-25T10:51:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-woocommerce-auth-bypass/","summary":"An authorization bypass vulnerability in the Customer Reviews for WooCommerce plugin for WordPress allows unauthenticated attackers to delete arbitrary files from the WordPress Media Library.","title":"Authorization Bypass in Customer Reviews for WooCommerce Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-woocommerce-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Customer Reviews for WooCommerce (\u003c= 5.120.0)","version":"https://jsonfeed.org/version/1.1"}