CVE-2026-100517: WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object References (IDOR) vulnerability
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Photo Reviews for WooCommerceto a version that resolves this vulnerability.Fixed in 1.2.31
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. The supplied vector indicates it can be exploited remotely with low attack complexity and no user interaction.
What versions are affected?
Photo Reviews for WooCommerce versions up to and including 1.2.30 are identified as affected.
What is the likely security impact?
The provided CVSS vector rates availability impact as high, while confidentiality and integrity impacts are listed as none. The issue is rated high severity with a score of 7.5.