Cusrev operates a niche e-commerce plugin ecosystem centered around customer review functionality for WooCommerce, where vulnerabilities cluster in access-control and input-handling mechanisms inherent to web-facing review submission and management. The recurring weakness classes—missing authorization, cross-site scripting, cross-site request forgery, sensitive-information exposure, and improper access control—reflect the authentication and validation demands of a user-generated-content plugin. Defenders deploying this plugin should prioritize review-submission endpoint hardening and access-control validation; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cusrev over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56043HIGH Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | Jun 26, 2026 | 7.1 | 29 | NO | NO |
CVE-2023-0080HIGH The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to i | Feb 13, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-38470HIGH Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. | Sep 23, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-40194HIGH Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress | Sep 23, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-6979HIGH The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in | Jan 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-38134HIGH Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. | Sep 23, 2022 | 8.8 | 22 | NO | NO |
CVE-2024-3731MEDIUM The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to | Apr 19, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-45101MEDIUM Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce customer-reviews-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels. | Jan 2, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-1044MEDIUM The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in al | Feb 29, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-10614MEDIUM The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up | Nov 16, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cusrev.
Media articles that mention a CVE ID that affects a product developed by Cusrev — matched by CVE ID, not by vendor name.