CVE-2026-101923 | Villatheme Photo Reviews Plugin up to 1.2.30 on WordPress Review Image Deletion delete_reviews_image wcpr_image_upload_id authorization

SecurityVulns

A vulnerability identified as problematic has been detected in Villatheme Photo Reviews Plugin up to 1.2.30 on WordPress. Impacted is the function delete_reviews_image of the component Review Image Deletion. This manipulation of the argument wcpr_image_upload_id causes missing authorization.

This vulnerability is registered as CVE-2026-101923. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More