CVE-2026-76585: Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Parameter
Published Aug 30, 2026
·Updated
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
wordpress/woocommerce<5.118.0
Event History
Aug 30, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated users can exploit it by submitting malicious content through an affected customer-review endpoint. No authenticated WordPress or WooCommerce account is required.
2
What versions are affected?
Customer Reviews for WooCommerce versions earlier than 5.118.0 are affected. Version 5.118.0 or later is not identified as affected by the provided information.
3
What is the impact of successful exploitation?
An attacker can cause malicious script content to be stored in customer reviews. That script may execute in the browser of users who view the affected review.