
CVE-2025-14452 The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7… https://www.cve.org/CVERecord?id=CVE-2025-14452
Post summary
The WP Customer Reviews plugin (versions ≤3.7) is disclosed to contain a reflected XSS flaw triggered through the 'wpcr3_fname' parameter, as documented in CVE-2025-14452.
