---
id: CVE-2026-76585
title: >-
  The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not
  sanitise and escape the content of customer reviews received via one of its
  endpoints, which could allow unauthenticated users to perform Stored
  Cross-Site Scr…
summary: >-
  The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not
  sanitise and escape the content of customer reviews received via one of its
  endpoints, which could allow unauthenticated users to perform Stored
  Cross-Site Scr…
severity: none
published: '2026-08-30'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76585'
references:
  - url: 'https://wpscan.com/vulnerability/7d539fba-d47e-461d-b40f-1aa8f535d506/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00276
epssPercentile: 0.20248
ingestedAt: '2026-08-30T15:54:21.905Z'
---

## Overview

The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
