• PoC PUBLIC

CVE-2026-89055: authorization bypass in ivole Customer Reviews for WooCommerce

Unauthenticated attackers can delete attachments from a WordPress site's Media Library in the Customer Reviews for WooCommerce plugin, tracked as CVE-2026-89055. Versions 5.120.0 and earlier on the 5.x branch are affected. Exploitation does not require a WordPress account; an attacker only needs access to a public review-form link that exposes the nonce used by the plugin's deletion handler.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00385
CWE
CWE-862
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code is available, so immediately mitigate exposure to public review-form links and harden access to the Media Library while awaiting a vendor fix.

What is CVE-2026-89055?

Unauthenticated attackers can delete attachments from a WordPress site's Media Library in the Customer Reviews for WooCommerce plugin, tracked as CVE-2026-89055. Versions 5.120.0 and earlier on the 5.x branch are affected. Exploitation does not require a WordPress account; an attacker only needs access to a public review-form link that exposes the nonce used by the plugin's deletion handler.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Which versions of ivole Customer Reviews for WooCommerce are affected?

BRANCHAFFECTEDFIXED
5.x5.120.0 and earlier

Is CVE-2026-89055 being exploited?

Public exploit code is available.

How to fix CVE-2026-89055

  1. Remove or disable public review-form links and stop distributing formId links to customers.
  2. Restrict access to the Media Library and review-related endpoints (block by IP, web application firewall rules, or authentication).
  3. Monitor logs for unexpected media deletions and back up Media Library content offsite.
  4. Follow the vendor's guidance and apply an official patch immediately once released.

Frequently asked questions

Is CVE-2026-89055 being actively exploited?

Public exploit code is available for CVE-2026-89055.

Which Customer Reviews for WooCommerce versions are affected by CVE-2026-89055?

Customer Reviews for WooCommerce on the 5.x branch, versions 5.120.0 and earlier, are affected.

Is there a patch for CVE-2026-89055?

No patched versions are listed for CVE-2026-89055 as of the provided data; follow vendor guidance for updates.

Does CVE-2026-89055 require authentication?

No, CVE-2026-89055 can be exploited without a WordPress account if the attacker has access to the public review-form link.

References