Skip to main content
Vulnerability Database/CVE-2026-89055

CVE-2026-89055: WooCommerce Customer Reviews Auth Bypass

CVE-2026-89055 is an authorization bypass flaw in Customer Reviews for WooCommerce that lets attackers delete arbitrary media files without authentication. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2026-89055 Overview

CVE-2026-89055 is an authorization bypass vulnerability in the Customer Reviews for WooCommerce plugin for WordPress, affecting all versions up to and including 5.120.0. The plugin fails to verify that a user is authorized to perform certain actions on review submissions. Unauthenticated attackers can permanently delete arbitrary attachments from the WordPress Media Library, including administrator-owned product images, logos, and documents. Exploitation requires only a public review-form link containing a 13-hex formId distributed to customers via email. That link exposes the nonce needed to reach the vulnerable handler without any WordPress account or session. The weakness is tracked under CWE-862: Missing Authorization.

Critical Impact

Unauthenticated attackers can permanently delete arbitrary Media Library attachments, destroying product images, branding assets, and documents site-wide.

Affected Products

  • Customer Reviews for WooCommerce plugin for WordPress
  • All versions up to and including 5.120.0
  • WordPress sites running WooCommerce with the plugin enabled

Discovery Timeline

  • 2026-09-25 - CVE-2026-89055 published to NVD
  • 2026-09-25 - Last updated in NVD database

Technical Details for CVE-2026-89055

Vulnerability Analysis

The Customer Reviews for WooCommerce plugin exposes AJAX handlers used to collect customer reviews through a public review form. The handler accepts attachment IDs supplied by the submitter and associates them with a review record. When that review is later trashed and purged, the referenced attachments are deleted along with it. The handler never checks whether the submitting user owns, uploaded, or has permission to modify the referenced attachments. An attacker who can reach the public form endpoint can therefore enumerate arbitrary attachment IDs and inject them into a review that will trigger their deletion. The result is permanent destruction of media assets owned by any user, including administrators.

Root Cause

The root cause is missing authorization in the review submission flow, consistent with CWE-862. Code paths in class-cr-local-forms-ajax.php, class-cr-endpoint.php, and class-cr-reviews.php process attachment IDs from untrusted request data without validating ownership or capability. The relevant source lines are documented in the WordPress Review Endpoint Code (Line 318) and WordPress Reviews Class Code (Line 1871).

Attack Vector

Exploitation is remote and requires no authentication. The attacker needs a public review-form link containing a 13-hex formId value, which is distributed to customers via email reminders. This link exposes the nonce required to invoke the AJAX handler. The attacker submits a review that references attachment IDs belonging to other users, then the natural trash-and-purge lifecycle of the review removes those attachments from the Media Library. See the Wordfence Vulnerability Report for additional detail.

No verified exploit code is published at this time. The vulnerability is described in prose based on the affected source file references above.

Detection Methods for CVE-2026-89055

Indicators of Compromise

  • Unexpected deletions of Media Library attachments, particularly product images, logos, and uploaded documents owned by administrators.
  • Review submissions originating from unknown IP addresses that reference the public review-form endpoint of the Customer Reviews for WooCommerce plugin.
  • Trashed or purged review records that contain attachment ID references outside the submitter's own uploads.
  • Access to review-form URLs containing 13-character hexadecimal formId values from sources other than legitimate reminder emails.

Detection Strategies

  • Audit wp_posts and wp_postmeta for attachment post deletions correlated with review submissions handled by class-cr-local-forms-ajax.php.
  • Enable WordPress action logging for delete_attachment and correlate initiating request context with review endpoint activity.
  • Inspect web server access logs for POST requests to the plugin's AJAX endpoints referencing attachment IDs the submitter did not upload.

Monitoring Recommendations

  • Monitor for bursts of review submissions tied to a single formId or source IP targeting the review handler.
  • Alert on administrator-owned attachments transitioning to a deleted state when no administrator session is active.
  • Track changes to the Customer Reviews for WooCommerce plugin version and confirm installed builds are above 5.120.0.

How to Mitigate CVE-2026-89055

Immediate Actions Required

  • Update the Customer Reviews for WooCommerce plugin to a version newer than 5.120.0 as soon as a patched release is available.
  • Audit the Media Library for missing attachments and restore from backups where destruction has already occurred.
  • Rotate or invalidate outstanding public review-form links containing formId values that may have been exposed.

Patch Information

The vendor's remediation is tracked in the WordPress Plugin Change Set. Administrators should install the fixed release through the WordPress plugin updater and verify the installed version is greater than 5.120.0. Review the Wordfence Vulnerability Report for the authoritative fixed-version reference.

Workarounds

  • Disable the Customer Reviews for WooCommerce plugin until the patched version can be deployed.
  • Restrict access to the review-form AJAX endpoints at the web server or WAF layer, blocking unauthenticated requests that include attachment ID parameters.
  • Suspend outbound review reminder emails to avoid distributing new public form links with exposed nonces until patching is complete.
  • Maintain tested, off-site backups of the Media Library so that destroyed attachments can be restored quickly.
bash
# Example nginx rule to block anonymous POSTs to the vulnerable AJAX action
location = /wp-admin/admin-ajax.php {
    if ($request_method = POST) {
        set $block 0;
        if ($args ~* "action=cr_(local_form|review)") { set $block 1; }
        if ($http_cookie !~* "wordpress_logged_in_") { set $block "${block}1"; }
        if ($block = "11") { return 403; }
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.