
CVE-2026-1316 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and inclu… https://www.cve.org/CVERecord?id=CVE-2026-1316
Post summary
CVE-2026-1316 exposes a stored XSS flaw in the WooCommerce Customer Reviews plugin, leveraging the media[].href parameter across all affected versions.

