---
id: CVE-2026-11608
title: >-
  The WP Customer Reviews plugin for WordPress is vulnerable to Reflected
  Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to,
  and including, 3.7.8 due to insufficient input sanitization and output
  escaping
summary: >-
  The WP Customer Reviews plugin for WordPress is vulnerable to Reflected
  Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to,
  and including, 3.7.8 due to insufficient input sanitization and output
  escaping. This mak…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: bompus
product: WP Customer Reviews
affected:
  - wp_customer_reviews <= 3.7.8
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11608'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-customer-reviews/tags/3.7.7/include/templates/frontend_review_form_text_field.html#L13
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-customer-reviews/tags/3.7.7/wp-customer-reviews-3.php#L1051
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-customer-reviews/tags/3.7.7/wp-customer-reviews-3.php#L257
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-customer-reviews/tags/3.7.7/wp-customer-reviews-3.php#L272
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-customer-reviews/trunk/include/templates/frontend_review_form_text_field.html#L13
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-customer-reviews/trunk/wp-customer-reviews-3.php#L1051
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-customer-reviews/trunk/wp-customer-reviews-3.php#L257
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-customer-reviews/trunk/wp-customer-reviews-3.php#L272
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3571227%40wp-customer-reviews&new=3571227%40wp-customer-reviews
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/0e0332d1-b83b-4347-95ef-3429de5a8cca?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00332
epssPercentile: 0.23709
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:24:58.436485Z'
ingestedAt: '2026-09-19T07:59:56.115Z'
---

## Overview

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
