Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4664

22
FAUCET Score

OVERVIEW The Customer Reviews for WooCommerce plugin for WordPress versions up to 5.103.0 contains an authentication bypass vulnerability in its review submission REST API endpoint. The flaw exists in the create_review_permissions_check() function, which fails to validate that stored authentication keys are non-empty before comparison. This allows unauthenticated attackers to bypass permission controls and submit, modify, or inject product reviews via the POST /ivole/v1/review endpoint. SEVERITY The vulnerability is network-accessible with low attack complexity and requires no user interaction or authentication, making it easily exploitable by remote attackers. The CVSS v3.1 score of 5.3 (MEDIUM) reflects limited integrity impact, as the primary risk involves unauthorized review creation and modification. The attack surface is particularly concerning because reviews are auto-approved by default, enabling attackers to inject malicious or defamatory content immediately without administrator review. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and has not been added to any hot list tracking. However, the FAUCET risk score of 41.0/100 and relatively straightforward exploitation method suggest organizations should apply patches promptly to prevent potential abuse. Community attention remains minimal at this time.

Impacted Technologies

VendorProductVersion(s)CPE
IvoleCustomer Reviews For WooCommerce
>= 0, <= 5.103.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.67%
Probability of exploitation in next 30 days
EPSS Percentile
48.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0067 is in the 30th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/customer-reviews-woocommerce/tags/5.102.0/includes/emails/class-cr-email.php
plugins.trac.wordpress.org / browser/customer-reviews-woocommerce/tags/5.102.0/includes/reviews/class-cr-endpoint.php
plugins.trac.wordpress.org / browser/customer-reviews-woocommerce/tags/5.102.0/includes/reviews/class-cr-endpoint.php
plugins.trac.wordpress.org / browser/customer-reviews-woocommerce/tags/5.102.0/includes/reviews/class-cr-endpoint.php
plugins.trac.wordpress.org / changeset
wordpress.org / plugins/customer-reviews-woocommerce
wordfence.com / threat-intel/vulnerabilities/id/27e3dfe3-ad33-4d0c-a999-d0734df2f59b