Loading market data...
← Back to CVE feed

CVE-2026-76585

UNKNOWN View on NVD ↗

Description

The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

Published: Aug 30, 2026 07:17 UTC Modified: Aug 30, 2026 07:17 UTC