Vendor
Unauthenticated attackers can perform Stored Cross-Site Scripting (XSS) via the 'cr_local_forms_submit' AJAX action in Customer Reviews for WooCommerce versions 5.106.0 and below.