---
id: CVE-2026-89055
title: >-
  The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to
  authorization bypass in all versions up to, and including, 5.120.0
summary: >-
  The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to
  authorization bypass in all versions up to, and including, 5.120.0. This is
  due to the plugin not properly verifying that a user is authorized to perform
  an actio…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-862
vendor: ivole
product: Customer Reviews for WooCommerce
affected:
  - customer_reviews_for_woocommerce <= 5.120.0
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T14:17:21.510'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89055'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reminders/class-cr-local-forms-ajax.php#L57
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-endpoint.php#L318
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-endpoint.php#L467
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-reviews.php#L129
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-reviews.php#L1871
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3694303%40customer-reviews-woocommerce&new=3694303%40customer-reviews-woocommerce
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/b7bbeeea-3888-42a6-8d14-f5c39f5dcb70?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00385
epssPercentile: 0.29793
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/murrez/CVE-2026-89055'
  checkedAt: '2026-09-25T15:11:30.192Z'
exploitAvailable: true
ingestedAt: '2026-09-25T07:01:12.111Z'
---

## Overview

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product images, logos, and documents — by injecting their IDs into a review that is later trashed and purged. Exploitation requires a public review-form link (a 13-hex formId distributed to customers via e-mail), which exposes the nonce needed to reach the handler without any WordPress account or session.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
