Cusrev Customer Reviews Woocommerce
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Cusrev Customer Reviews Woocommerce.
By the Year
In 2026 there have been 0 vulnerabilities in Cusrev Customer Reviews Woocommerce. Last year, in 2025 Customer Reviews Woocommerce had 1 security vulnerability published. Right now, Customer Reviews Woocommerce is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 1 | 4.30 |
| 2024 | 8 | 5.35 |
| 2023 | 1 | 8.80 |
| 2022 | 3 | 8.37 |
It may take a day or so for new Customer Reviews Woocommerce vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Cusrev Customer Reviews Woocommerce Security Vulnerabilities
CusRev Customer Reviews for WooCommerce: Missing Auth (5.36.0)
CVE-2023-45101
4.3 - Medium
- January 02, 2025
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through 5.36.0.
AuthZ
WooCommerce Customer Reviews Plugin: Unauthorized Access via Missing Capability Check in cancel_impo
CVE-2024-10614
4.3 - Medium
- November 16, 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import or check on the status.
AuthZ
WooCommerce Customer Reviews XSS via 's' param <5.47.0
CVE-2024-3731
6.1 - Medium
- April 19, 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
XSS
WooCommerce CustRev Plugin: Unauthorized Coupon Access via Missing Cap Check
CVE-2024-3869
4.3 - Medium
- April 16, 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
AuthZ
Customer Reviews for WooCommerce: unauth email send via send_test_email 5.46.0
CVE-2024-3243
4.3 - Medium
- April 16, 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.
AuthZ
Unauthorized Review Submission in WooCommerce Customer Reviews <=5.38.12
CVE-2024-1044
5.3 - Medium
- February 29, 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email addresses regardless of whether reviews are globally enabled.
Authorization
Missing Auth in CusRev Customer Reviews for WooCommerce <=5.38.1
CVE-2023-51692
4.3 - Medium
- February 28, 2024
Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.
AuthZ
Customer Reviews for WooCommerce WP Plugin XSS via Shortcode Attrs Pre-5.17.0
CVE-2023-0079
5.4 - Medium
- January 16, 2024
The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
XSS
WC Customer Reviews <=5.38.9 file upload via ivole_import_upload_csv (auth)
CVE-2023-6979
8.8 - High
- January 11, 2024
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Unrestricted File Upload
WooCommerce Customer Reviews WP Plugin <5.16.0 RCE via Shortcode File Inclusion
CVE-2023-0080
8.8 - High
- February 13, 2023
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.
Directory traversal
Unauthenticated Info Disclosure in WooCommerce Customer Reviews <=5.3.5
CVE-2022-40194
7.5 - High
- September 23, 2022
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress
Information Disclosure
WooCommerce Customer Reviews 5.3.5 CSRF Vulnerability
CVE-2022-38470
8.8 - High
- September 23, 2022
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
Session Riding
Auth+ BAccess Ctrl v4.5 in Customer Reviews for WooCommerce <=5.3.5
CVE-2022-38134
8.8 - High
- September 23, 2022
Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Cusrev Customer Reviews Woocommerce or by Cusrev? Click the Watch button to subscribe.