
CVE-2026-3355 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and includ… https://www.cve.org/CVERecord?id=CVE-2026-3355
Post summary
CVE‑2026‑3355 reveals a reflected XSS vulnerability in the WooCommerce Customer Reviews plugin that can be triggered via the ‘crsearch’ parameter; no PoC, exploit, patch, or active exploitation information is provided.
