Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-4664 - Customer Reviews Woocommerce Plugin
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict equality (`===`), without verifying that the stored key is non-empty. For orders where no review reminder email has been sent, the `ivole_secret_key` meta is not set, causing `get_meta()` to return an empty string. An attacker can supply `key: ""` to match this empty value and bypass the permission check.…
CVE-2026-4664
CVE-2025-14891 - Customer Reviews Woocommerce Plugin
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. While it is possible to invoke the AJAX action without authentication, the attacker would need to know a valid form ID, which requires them to place an…
CVE-2025-14891
CVE-2025-5720 - Customer Reviews Woocommerce Plugin
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-5720
CVE-2024-3869 - Customer Reviews Woocommerce Plugin
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
CVE-2024-3869
CVE-2024-3243 - Customer Reviews Woocommerce Plugin
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.
CVE-2024-3243
CVE-2023-6979 - Customer Reviews Woocommerce Plugin
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2023-6979
CVE-2022-40194 - Customer Reviews Woocommerce Plugin
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin
CVE-2022-40194
CVE-2022-38470 - Customer Reviews Woocommerce Plugin
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin
CVE-2022-38470
CVE-2022-38134 - Customer Reviews Woocommerce Plugin
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin
CVE-2022-38134
