CVE-2026-12684
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of
CVSS
6.5
Medium
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Published: Jul 16, 2026 · Last modified: Jul 16, 2026 · CWE-434
0.2%EPSS · 30 days0.2%
2026-07-162026-07-20
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist) to the Media Library and create attachment posts, leading to media library pollution and disk space exhaustion.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-562919.8 CRI94.5%
KEV—78Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability10dCVE-2026-562909.8 CRI85.5%
KEV—76Joomlack Page Builder Improper Access Control Vulnerability12dCVE-2026-489089.8 CRI72.6%
KEV—72JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability12dCVE-2026-489399.8 CRI71.5%
KEV—71iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability10dCVE-2023-388368.8 HIG99.3%
——30File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.12dCVE-2023-464747.2 HIG97.3%
——29File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.12d