CVE-2026-101923
Received Received - Intake

Arbitrary Content Deletion in Photo Reviews for WooCommerce

Vulnerability report for CVE-2026-101923, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker's review (or when WordPress's built-in wp_scheduled_delete cron empties the comment trash after 30 days).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
woocommerce photo_reviews to 1.2.30 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Photo Reviews for WooCommerce plugin for WordPress has a flaw allowing unauthenticated attackers to delete arbitrary posts, pages, products, or media attachments. This happens when attackers submit reviews with manipulated image IDs, which are stored without verification. When an admin deletes the review, the plugin unconditionally deletes the referenced attachments.

Detection Guidance

Check for unauthorized deletions in WordPress logs or database. Review comments with the wcpr_image_upload_id parameter in review submissions. Look for suspicious review submissions containing post IDs not owned by the submitter.

Impact Analysis

This vulnerability allows attackers to permanently delete critical content on your WordPress site, including posts, pages, products, or media files. If an administrator deletes a malicious review, the plugin will delete the referenced attachments without checking ownership, potentially causing data loss or site disruption.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized deletion of sensitive data. If personal or health-related content is stored as posts, pages, or media attachments, attackers could remove it permanently, violating data integrity and access requirements. GDPR mandates data integrity and availability, while HIPAA requires protection of health information integrity. Unauthorized deletion risks breaches of these standards.

Mitigation Strategies

Update the Photo Reviews for WooCommerce plugin to the latest version. Disable the plugin if an update is unavailable. Monitor for unauthorized deletions and restrict user permissions to prevent untrusted submissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101923. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart