CVE-2026-96823: WordPress Customer Reviews for WooCommerce plugin <= 5.120.0 - Arbitrary Content Deletion vulnerability
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Customer Reviews for WooCommerce Pluginto a version that resolves this vulnerability.Fixed in 5.121.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. The network attack vector and low attack complexity indicate it can be attempted remotely with no user interaction.
What is the practical impact?
Successful exploitation can delete arbitrary content, resulting in a high availability impact. The provided scoring indicates no direct confidentiality or integrity impact.
Which installations should be considered affected?
Installations using CusRev Customer Reviews for WooCommerce version 5.120.0 or earlier should be considered affected. The supplied data does not identify a workaround, mitigation, or fixed version.