CVE-2026-97663 Overview
CVE-2026-97663 is a stored cross-site scripting (XSS) vulnerability in the Customer Reviews for WooCommerce plugin for WordPress. The flaw affects all versions up to and including 5.122.0. The plugin fails to sanitize the comment author name on input and does not escape it on output. Unauthenticated attackers can inject arbitrary JavaScript into pages that render reviews. Exploitation requires the image attachment feature (ivole_attach_image) to be enabled so that a review can be submitted alongside an image upload through the public wp_ajax_nopriv_cr_upload_local_images_frontend endpoint. The injected script executes in the browser of any user who loads the affected page.
Critical Impact
Unauthenticated attackers can store JavaScript that executes against site visitors and administrators, enabling session theft, account takeover, and administrative action hijacking.
Affected Products
- Customer Reviews for WooCommerce plugin for WordPress
- All versions up to and including 5.122.0
- Installations with the ivole_attach_image image attachment feature enabled
Discovery Timeline
- 2026-10-02 - CVE-2026-97663 published to the National Vulnerability Database (NVD)
- 2026-10-02 - Last updated in NVD database
Technical Details for CVE-2026-97663
Vulnerability Analysis
The vulnerability is a stored cross-site scripting flaw classified as [CWE-79]. The Customer Reviews for WooCommerce plugin accepts a review author name from unauthenticated users and persists it without sufficient sanitization. When the stored review is rendered, the author name is emitted without proper output escaping, allowing the browser to execute attacker-controlled script. Because reviews are rendered on product pages and in the WordPress administrative review list, both site visitors and authenticated administrators are exposed. Script execution in an administrator context can be chained to perform privileged actions, create backdoor accounts, or inject persistent web shells through plugin or theme editors.
Root Cause
The root cause is twofold: insufficient input sanitization of the comment author name field and missing output escaping when that field is rendered. The plugin accepts an entity-encoded malicious author name on submission, which bypasses naive filters, and the stored value is later decoded or echoed in a context where it is interpreted as HTML. Relevant code paths exist in class-cr-reviews.php and class-cr-reviews-list-table.php within the plugin tree at version 5.122.0.
Attack Vector
The attack is network-based and requires no authentication or user interaction beyond a victim visiting an affected page. The attacker submits a review containing an entity-encoded payload in the author name field and uploads an attached image through the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend AJAX endpoint. The image attachment feature (ivole_attach_image) must be enabled on the target site. Once the review renders, the payload executes in the context of the WordPress origin.
See the plugin source for class-cr-reviews.php and the reviews list table source for the vulnerable rendering paths. No public proof-of-concept exploit is listed for this CVE.
Detection Methods for CVE-2026-97663
Indicators of Compromise
- Review submissions where the author name field contains HTML entities, angle brackets, or JavaScript keywords such as onerror, onload, <script, or javascript:.
- Unusual POST requests to admin-ajax.php with the action cr_upload_local_images_frontend from unauthenticated clients.
- WordPress review entries whose author display value renders as empty or malformed HTML in the admin review list.
- Unexpected outbound requests from administrator browsers immediately after loading the plugin's review management page.
Detection Strategies
- Inspect the wp_comments table for comment author values containing script tags, event handlers, or entity-encoded payloads targeting the parser.
- Monitor web server access logs for POSTs to wp-admin/admin-ajax.php carrying action=cr_upload_local_images_frontend paired with review submission requests from the same source IP.
- Deploy a web application firewall rule that flags review submissions whose author name field contains HTML control characters.
Monitoring Recommendations
- Alert on administrator session anomalies such as new user creation or plugin modifications shortly after a review was submitted.
- Enable Content Security Policy reporting to capture inline script execution attempts on review pages.
- Audit recently installed plugins, themes, and administrator accounts if indicators are observed.
How to Mitigate CVE-2026-97663
Immediate Actions Required
- Update the Customer Reviews for WooCommerce plugin to the patched release that follows version 5.122.0.
- If updating immediately is not possible, disable the image attachment feature (ivole_attach_image) to remove the required exploitation precondition.
- Review the wp_comments table and the plugin's review storage for malicious author names and remove or sanitize affected entries.
- Rotate administrator credentials and invalidate active sessions if indicators of compromise are present.
Patch Information
The vendor addressed the issue in a release tracked by WordPress Plugin Changeset 3716157. Additional details are available in the Wordfence vulnerability entry. Administrators should apply the update through the WordPress plugin manager or by replacing the plugin files with the patched version.
Workarounds
- Disable the ivole_attach_image option in the plugin settings to break the exploitation chain requiring the public image upload endpoint.
- Require review moderation so administrators approve new reviews before they are rendered to visitors.
- Deploy a WAF rule that blocks review submissions containing HTML tags or event-handler attributes in the author name field.
- Temporarily deactivate the plugin on high-value storefronts until the patched version is installed.
# Configuration example: block the public upload endpoint until patched
# nginx snippet to deny unauthenticated access to the vulnerable AJAX action
if ($arg_action = "cr_upload_local_images_frontend") {
return 403;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.