<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Photo Reviews for WooCommerce (&lt;= 1.2.30) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/photo-reviews-for-woocommerce--1.2.30/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 06:53:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/photo-reviews-for-woocommerce--1.2.30/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Content Deletion in Photo Reviews for WooCommerce Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-photo-reviews-wc-vuln/</link><pubDate>Sat, 03 Oct 2026 06:53:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-photo-reviews-wc-vuln/</guid><description>An unauthenticated arbitrary content deletion vulnerability in the Photo Reviews for WooCommerce plugin (CVE-2026-101923) allows attackers to delete arbitrary site posts, pages, or media by injecting malicious IDs into review metadata.</description><content:encoded><![CDATA[<p>The Photo Reviews for WooCommerce plugin for WordPress, in versions 1.2.30 and below, contains a critical security flaw that allows for unauthorized content deletion. The vulnerability stems from the plugin's failure to validate the wcpr_image_upload_id parameter during public review submissions. An unauthenticated attacker can submit a review containing an arbitrary post ID, which the plugin stores in the review's comment metadata.</p>
<p>The plugin's delete_reviews_image() handler later processes this metadata by calling wp_delete_post() on the stored IDs. Consequently, when an administrator deletes the malicious review, or when the wp_scheduled_delete cron job purges the comment trash, the system unknowingly deletes the site content corresponding to the injected IDs. This impact includes the permanent loss of products, posts, pages, and media attachments. The vulnerability was disclosed via the NVD, and users are advised to upgrade to a version that addresses the lack of ownership verification on submitted image metadata IDs.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to the permanent, unauthorized deletion of arbitrary site data, including essential WooCommerce product pages, blog posts, media attachments, and administrative pages. If widely exploited, this vulnerability could cause massive site data loss, significant service disruption, and potential financial impact for e-commerce operators relying on the affected WooCommerce installation.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for administrators:</p>
<ul>
<li>Immediately update the &quot;Photo Reviews for WooCommerce&quot; plugin to the latest version (above 1.2.30) where verification of metadata IDs has been implemented.</li>
<li>Review database or system logs for suspicious review submissions containing unconventional or unexpected ID values in the wcpr_image_upload_id parameter.</li>
<li>Disable the &quot;Photo Reviews for WooCommerce&quot; plugin until a patch is applied if the site cannot be updated immediately.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>