{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/customer-reviews-for-woocommerce/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cusrev:customer_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-6176"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Customer Reviews for WooCommerce (\u003c= 5.106.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Customer Reviews for WooCommerce"],"content_html":"\u003cp\u003eThe Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to and including 5.106.0. The vulnerability stems from the plugin's 'cr_local_forms_submit' AJAX action, which fails to adequately sanitize user-supplied review content before it is stored in the database via the 'wp_insert_comment' function. Furthermore, the plugin fails to perform proper output escaping when rendering this content on product pages using 'comment_text()'.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can exploit this by submitting malicious scripts within review comments. By leveraging legitimate review form URLs, typically delivered via email to previous customers, an attacker can inject scripts that execute in the browser of any user who views the compromised product page. Successful exploitation may lead to session hijacking, unauthorized actions performed on behalf of authenticated administrators or users, or redirection to malicious sites.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the context of victim browsers. This poses a significant risk to WordPress sites using the plugin, particularly if administrative accounts view the affected product pages. Potential consequences include account takeover, credential theft, and unauthorized site modifications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'Customer Reviews for WooCommerce' plugin to the latest version immediately to patch CVE-2026-6176.\u003c/li\u003e\n\u003cli\u003eAudit existing product comments for unexpected HTML or script tags if the site was running version 5.106.0 or earlier.\u003c/li\u003e\n\u003cli\u003eImplement or strengthen Content Security Policy (CSP) headers to restrict the execution of unauthorized inline scripts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T17:13:47Z","date_published":"2026-08-28T17:13:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-woocommerce-xss/","summary":"Unauthenticated attackers can perform Stored Cross-Site Scripting (XSS) via the 'cr_local_forms_submit' AJAX action in Customer Reviews for WooCommerce versions 5.106.0 and below.","title":"Stored Cross-Site Scripting in Customer Reviews for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-08-woocommerce-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Customer Reviews for WooCommerce","version":"https://jsonfeed.org/version/1.1"}