---
id: CVE-2026-14941
title: >-
  The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not
  perform nonce or capability checks on several settings-related AJAX actions,
  allowing users with minimal permissions such as Subscribers to invoke
  administrati…
summary: >-
  The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not
  perform nonce or capability checks on several settings-related AJAX actions,
  allowing users with minimal permissions such as Subscribers to invoke
  administrati…
severity: none
published: '2026-08-10'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14941'
references:
  - url: 'https://wpscan.com/vulnerability/572ba4a2-1b51-4631-9c28-7cc3d44f0761/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-10T07:39:17.623Z'
epss: 0.00168
epssPercentile: 0.06435
---

## Overview

The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
