CVE-2026-101923: Photo Reviews for WooCommerce <= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcprimageuploadid parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the deletereviewsimage() handler unconditionally calling wpdeletepost( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker's review (or when WordPress's built-in wpscheduleddelete cron empties the comment trash after 30 days).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Unauthenticated attackers can submit a public review containing attacker-controlled post IDs. Exploitation does not require WordPress credentials, but it requires the site to allow public review submission.
What event triggers deletion of the targeted content?
The attacker-controlled IDs are deleted when the associated malicious review is deleted. This can occur when an administrator deletes the review or when WordPress's built-in wp_scheduled_delete cron job empties the comment trash after 30 days.
What content can be deleted?
The affected deletion handler can permanently delete arbitrary WordPress posts, pages, WooCommerce products, and media attachments identified by the stored IDs.
How can I determine whether a site may already be targeted?
Review submissions and review comment metadata for unexpected values in the reviews-images metadata associated with wcpr_image_upload_id. Also investigate reviews that were deleted or automatically purged, particularly where posts, pages, products, or attachments were unexpectedly removed.