Known Vulnerabilities for WP Customer Reviews by Bompus
Listed below are 10 of the newest known vulnerabilities associated with "WP Customer Reviews" by "Bompus".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-97663 json | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Nam... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-96823 json | Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-94274 json | The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer revie... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-89055 json | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and in... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-76585 json | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer rev... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-14942 json | Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugi... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-14941 json | The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several s... | Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2026-13771 json | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode ... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-12684 json | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce ch... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-11608 json | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter ... | Not Provided | 2026-09-19 | 2026-09-19 |