CVE-2026-97663 | ivole Customer Reviews for WooCommerce Plugin up to 5.122.0 on WordPress Image Attachment Feature wp_ajax_nopriv_cr_upload_local_images_frontend Comment Author Name cross site scripting
A vulnerability marked as problematic has been reported in ivole Customer Reviews for WooCommerce Plugin up to 5.122.0 on WordPress. Impacted is the function wp_ajax_nopriv_cr_upload_local_images_frontend of the component Image Attachment Feature. This manipulation of the argument Comment Author Name causes cross site scripting.
This vulnerability is handled as CVE-2026-97663. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More