CVE-2026-100515: WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VillaTheme Photo Reviews for WooCommerceto a version that resolves this vulnerability.Fixed in 1.2.31
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using VillaTheme Photo Reviews for WooCommerce version 1.2.30 or earlier are affected. The issue is remotely reachable and does not require the attacker to have privileges.
What does an attacker need to exploit it?
Exploitation requires a user to interact with attacker-controlled content, as indicated by the UI:R vector. The available data identifies the flaw as reflected XSS but does not specify the affected request parameter or interaction path.
What is the impact if exploitation succeeds?
Successful exploitation can affect confidentiality, integrity, and availability at a low level, and the scope may extend beyond the vulnerable component. The severity vector is CVSS 7.1 high.