DIRAS TAKE
Urgent: public exploit code is available, so immediately mitigate exposure to public review-form links and harden access to the Media Library while awaiting a vendor fix.
What is CVE-2026-89055?
Unauthenticated attackers can delete attachments from a WordPress site's Media Library in the Customer Reviews for WooCommerce plugin, tracked as CVE-2026-89055. Versions 5.120.0 and earlier on the 5.x branch are affected. Exploitation does not require a WordPress account; an attacker only needs access to a public review-form link that exposes the nonce used by the plugin's deletion handler.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Which versions of ivole Customer Reviews for WooCommerce are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 5.x | 5.120.0 and earlier |
Is CVE-2026-89055 being exploited?
Public exploit code is available.
How to fix CVE-2026-89055
- Remove or disable public review-form links and stop distributing formId links to customers.
- Restrict access to the Media Library and review-related endpoints (block by IP, web application firewall rules, or authentication).
- Monitor logs for unexpected media deletions and back up Media Library content offsite.
- Follow the vendor's guidance and apply an official patch immediately once released.
Frequently asked questions
Is CVE-2026-89055 being actively exploited?
Public exploit code is available for CVE-2026-89055.
Which Customer Reviews for WooCommerce versions are affected by CVE-2026-89055?
Customer Reviews for WooCommerce on the 5.x branch, versions 5.120.0 and earlier, are affected.
Is there a patch for CVE-2026-89055?
No patched versions are listed for CVE-2026-89055 as of the provided data; follow vendor guidance for updates.
Does CVE-2026-89055 require authentication?
No, CVE-2026-89055 can be exploited without a WordPress account if the attacker has access to the public review-form link.
References
- nvd.nist.gov/vuln/detail/CVE-2026-89055
- cve.org/CVERecord?id=CVE-2026-89055
- wordfence.com/threat-intel/vulnerabilities/id/b7bbeeea-3888-42a6-8d14-f5c39f5dcb70?source=cve
- plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-reviews.php#L1871
- plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reminders/class-cr-local-forms-ajax.php#L57
- plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-endpoint.php#L318
- plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-endpoint.php#L467
- plugins.trac.wordpress.org/browser/customer-reviews-woocommerce/tags/5.120.0/includes/reviews/class-cr-reviews.php#L129
- plugins.trac.wordpress.org/changeset?reponame=&old=3694303%40customer-reviews-woocommerce&new=3694303%40customer-reviews-woocommerce
- All ivole CVEs on CVE Radar
- CVEs published in September 2026