Etavrian
keyboard_arrow_right Created with Sketch.
News
keyboard_arrow_right Created with Sketch.

80k WooCommerce stores silently exposed - see if this review plugin puts you at risk

Reviewed:
Andrii Daniv
1
min read
Jul 31, 2025
Alt text for image conveying urgent WooCommerce plugin vulnerability patching with cracked puzzle icon alert and worried store owner pointing to update button

Wordfence has disclosed a stored cross-site scripting (XSS) vulnerability in the Customer Reviews for WooCommerce plugin that could expose more than 80,000 WordPress stores to attack. The security firm published its advisory on 6 June 2024.

How the flaw works

Versions up to 5.80.2 do not sanitize the "author" parameter or properly escape the value when it is rendered. An unauthenticated attacker can therefore inject malicious JavaScript that executes for every visitor who views the affected page, turning the XSS into a site-wide threat.

Key details at a glance

  • Affected plugin: Customer Reviews for WooCommerce (≤ 5.80.2)
  • Active installations: about 80,000 sites
  • Attack vector: stored XSS, no login required
  • Patched release: 5.81.0, issued by CusRev after Wordfence notification
  • Disclosure date: 6 June 2024

Why it matters for store owners

The plugin is popular among WooCommerce merchants because it solicits post-purchase feedback and displays verified ratings that can boost sales. A successful XSS exploit could let an attacker steal customer data, redirect shoppers to malicious sites, or take administrative actions, undermining trust and revenue.

Recommended action

Site administrators should update to version 5.81.0 or later immediately. After patching, clear caches and review site logs for unusual activity to ensure no payloads remain in stored content.

Sources

Quickly summarize and get insighs with: 
Author
Andrew Daniv, Andrii Daniv
Andrii Daniv
Andrii Daniv is the founder and owner of Etavrian, a performance-driven agency specializing in PPC and SEO services for B2B and e‑commerce businesses.
Reviewed
Andrew Daniv, Andrii Daniv
Andrii Daniv
Andrii Daniv is the founder and owner of Etavrian, a performance-driven agency specializing in PPC and SEO services for B2B and e‑commerce businesses.
Quickly summarize and get insighs with: 
Table of contents