PT-2026-20619 · WordPress · Wp Customer Reviews

Athiwat Tiprasaharn

+6

·

Publicado

2026-02-19

·

Atualizado

2026-02-19

·

CVE-2025-14452

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Customer Reviews versions prior to 3.7.6
Description The WP Customer Reviews plugin for WordPress is susceptible to Reflected Cross-Site Scripting. This is due to inadequate input sanitization and output escaping of the wpcr3 fname parameter. An unauthenticated attacker can inject arbitrary web scripts into pages, which will execute if a user is tricked into performing an action, such as clicking a malicious link.
Recommendations Update WP Customer Reviews to version 3.7.6 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14452

Produtos afetados

Wp Customer Reviews