{"id":"CVE-2026-14941","title":"The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrati…","summary":"The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrati…","severity":"none","published":"2026-08-10","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14941","references":[{"url":"https://wpscan.com/vulnerability/572ba4a2-1b51-4631-9c28-7cc3d44f0761/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-10T07:39:17.623Z","epss":0.00168,"epssPercentile":0.06438,"slug":"CVE-2026-14941","body":"## Overview\n\nThe Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}