CRITICAL
ivole
CVE published 2026-09-25
CVE-2026-89055
The Customer Reviews for WooCommerce plugin for WordPress has a critical vulnerability allowing unauthorized deletion of Media Library attachments. This issue, tracked as CVE-2026-89055, affects all versions up to and including 5.120.0. Exploitation requires a public review-form link, exposing a nonce for deleting arbitrary attachments, including administrator-owned images and documents.