CVE-2026-89055
Received Received - Intake

Authorization Bypass Leading to Media Library Deletion in WooCommerce Customer Reviews Plugin

Vulnerability report for CVE-2026-89055, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: Wordfence

Description

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library β€” including administrator-owned product images, logos, and documents β€” by injecting their IDs into a review that is later trashed and purged. Exploitation requires a public review-form link (a 13-hex formId distributed to customers via e-mail), which exposes the nonce needed to reach the handler without any WordPress account or session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
woocommerce customer_reviews to 5.120.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in the Customer Reviews for WooCommerce plugin for WordPress. It allows unauthenticated attackers to permanently delete arbitrary attachments from the Media Library by exploiting a flaw where the plugin fails to verify user authorization. Attackers can inject attachment IDs into a review, then trash and purge the review to delete the files, including administrator-owned product images, logos, and documents.

Detection Guidance

Check WordPress installations for the Customer Reviews for WooCommerce plugin versions up to 5.120.0. Look for unauthorized deletion of media library files or suspicious review activity with public formId links.

Impact Analysis

If exploited, this vulnerability could lead to loss of critical media files such as product images, logos, and documents. It may disrupt business operations, damage brand reputation, and cause data loss. Attackers could also delete files that are essential for compliance or customer trust.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in the unauthorized deletion or loss of sensitive data stored in the Media Library. GDPR requires data integrity and protection, while HIPAA mandates safeguarding protected health information. Unauthorized deletion may violate these regulations.

Mitigation Strategies

Update the Customer Reviews for WooCommerce plugin to the latest version. Disable public review forms if not needed. Review Media Library for unauthorized deletions and restrict access to review management.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89055. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart