CVE-2026-28132
Cross-Site Scripting in WooCommerce Photo Reviews
Publication date: 2026-02-26
Last updated on: 2026-04-28
Assigner: Patchstack
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| villatheme | woocommerce_photo_reviews | to 1.4.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-80 | The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-28132 is a Content Injection vulnerability found in the WordPress WooCommerce Photo Reviews Plugin versions up to and including 1.4.4.
This vulnerability allows unauthenticated attackers to inject arbitrary content into website pages and posts by exploiting improper neutralization of script-related HTML tags, which is a form of basic Cross-Site Scripting (XSS).
Such injection could potentially enable attackers to insert phishing pages or malicious content into affected websites.
How can this vulnerability impact me? :
[{'type': 'paragraph', 'content': "The vulnerability can allow attackers to inject malicious content into your website's pages or posts without authentication."}, {'type': 'paragraph', 'content': "This could lead to the insertion of phishing pages or other harmful content, potentially damaging your website's reputation and trustworthiness."}, {'type': 'paragraph', 'content': 'However, the severity is considered low (CVSS score 5.3), and exploitation is regarded as unlikely.'}, {'type': 'paragraph', 'content': 'Currently, no official patch or mitigation is available, so affected users should be cautious and monitor their sites.'}] [1]
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know
What immediate steps should I take to mitigate this vulnerability?
There is no official patch currently available for this vulnerability in the WooCommerce Photo Reviews plugin up to version 1.4.4.
Since exploitation is considered unlikely due to the low severity, immediate mitigation steps are limited.
It is recommended to monitor for updates from the plugin developer and Patchstack for any forthcoming patches or mitigation advice.