← Back to the live CVE advisory feed

CVE-2026-101923: Photo Reviews for WooCommerce

Severity
8.1 (HIGH)
Vendor
VILLATHEME
Affected versions
0 through 1.2.30
Patch status
Unknown
Published
2026-10-03T06:16:39.603
Modified
2026-10-03T16:16:32.120

Why it matters

This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Check whether the affected WordPress plugin or theme is installed.
  • Update, disable, or remove the affected component if present.
  • Treat internet-facing systems as higher priority.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker's review (or when WordPress's built-in wp_scheduled_delete cron empties the comment trash after 30 days).

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 03, 2026 08:00 PM UTC
151 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-105105
AIT-Core
Reporter: 309F9EA4-E3E9-4C6C-B79D-E8EB01244F2C
9.8
CRITICAL
VIEW RECORD
CVE-2026-75937
IX Family
Reporter: E8A6BB0B-E373-42B1-A5DE-93E314325576
9.4
CRITICAL
VIEW RECORD
CVE-2026-105080
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-104019
sagemaker-distribution
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
9.3
CRITICAL
VIEW RECORD
CVE-2026-82042
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-95102
monta.app
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-84411
RouterOS PATCH
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-71885
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
9.2
CRITICAL
VIEW RECORD
CVE-2026-87115
VikAppointments Services Booking Calendar
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-92084
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-39718
Wallstreet
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-92536
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-97644
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-88783
Kubio AI Page Builder PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-18443
Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-105115
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-96451
Ultimate Member PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-82039
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-97363
Product identification pending
Reporter: ICS-CERT
8.7
HIGH
VIEW RECORD
CVE-2026-104433
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-71888
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-71889
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-71890
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-94591
Product identification pending
Reporter: ICS-CERT
8.6
HIGH
VIEW RECORD
CVE-2026-94592
Product identification pending
Reporter: ICS-CERT
8.6
HIGH
VIEW RECORD
CVE-2026-89236
SaveTo Wishlist Lite PATCH
Reporter: CONTACT
8.6
HIGH
VIEW RECORD
CVE-2026-94593
Product identification pending
Reporter: ICS-CERT
8.5
HIGH
VIEW RECORD
CVE-2026-104476
Product identification pending PATCH
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-91078
TillKit PATCH
Reporter: CONTACT
8.2
HIGH
VIEW RECORD
CVE-2026-71883
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-71886
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-71887
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-85515
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-103065
Kirki PATCH
Reporter: AUDIT
8.2
HIGH
VIEW RECORD
CVE-2026-104988
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-101923
Photo Reviews for WooCommerce
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-94505
Nelio Content – Editorial Calendar & Social Media Auto-Posting
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-104873
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-105119
Product identification pending PATCH
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-93428
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-101159
WP Ultimate Review PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-101160
WP Ultimate Review PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-101161
WP Ultimate Review PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-103514
WP 2FA PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-103913
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-97337
Simple Membership
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-75028
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-96267
WP Visitor Statistics (Real Time Traffic)
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-96270
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-92977
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-101928
Magic Tooltips For Contact Form 7
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-87091
Welcart e-Commerce
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-93430
GD Rating System
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-96564
SEOPress – AI SEO Plugin & On-site SEO
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-96575
Transliterator – Multilingual and Multi-script Text Conversion
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-96650
Strong Testimonials
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-97341
Visitor Traffic Real Time Statistics
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-93889
Mail logging & Catcher
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-97660
WPC Product Options for WooCommerce
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-104991
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-82045
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-105050
Product identification pending PATCH
Reporter: CVE
7.1
HIGH
VIEW RECORD
CVE-2026-104478
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-71891
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
7.1
HIGH
VIEW RECORD
CVE-2026-105113
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-103342
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
7.1
HIGH
VIEW RECORD
CVE-2026-82043
Product identification pending PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-93474
Product identification pending
Reporter: ICS-CERT
6.9
MEDIUM
VIEW RECORD
CVE-2026-97212
Product identification pending
Reporter: ICS-CERT
6.9
MEDIUM
VIEW RECORD
CVE-2026-105030
Product identification pending PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-71892
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
6.9
MEDIUM
VIEW RECORD
CVE-2026-105120
Product identification pending PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-105121
Product identification pending PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-103293
MPG PATCH
Reporter: CONTACT
6.8
MEDIUM
VIEW RECORD
CVE-2026-85568
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
6.8
MEDIUM
VIEW RECORD
CVE-2026-88782
Kubio AI Page Builder PATCH
Reporter: CONTACT
6.8
MEDIUM
VIEW RECORD
CVE-2026-94238
Loco Translate PATCH
Reporter: CONTACT
6.8
MEDIUM
VIEW RECORD
CVE-2026-94239
Loco Translate PATCH
Reporter: CONTACT
6.8
MEDIUM
VIEW RECORD
CVE-2026-85015
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
6.6
MEDIUM
VIEW RECORD
CVE-2026-103036
orpc PATCH
Reporter: SECURITY-ADVISORIES
6.5
MEDIUM
VIEW RECORD
CVE-2026-103918
orpc PATCH
Reporter: SECURITY-ADVISORIES
6.5
MEDIUM
VIEW RECORD
CVE-2026-82041
Product identification pending PATCH
Reporter: DISCLOSURE
6.5
MEDIUM
VIEW RECORD
CVE-2026-94539
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
6.5
MEDIUM
VIEW RECORD
CVE-2026-95865
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
6.5
MEDIUM
VIEW RECORD
CVE-2026-100152
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Reporter: SECURITY
6.5
MEDIUM
VIEW RECORD
CVE-2026-100157
WP Ultimate Review
Reporter: SECURITY
6.5
MEDIUM
VIEW RECORD
CVE-2026-94378
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2026-92727
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2025-12828
Ultra Addons Lite for Elementor
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2026-100148
Rich Showcase for Google Reviews
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2026-101162
WP Ultimate Review PATCH
Reporter: CONTACT
6.4
MEDIUM
VIEW RECORD
CVE-2026-97344
Wp Social Login and Register Social Counter
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2026-15795
Responsive Starter Templates – Elementor Templates & Starter Sites
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2026-92767
Twenty20 Image Before-After
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2026-104871
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
6.3
MEDIUM
VIEW RECORD
CVE-2026-82044
Product identification pending PATCH
Reporter: DISCLOSURE
6.3
MEDIUM
VIEW RECORD
CVE-2026-92923
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
6.3
MEDIUM
VIEW RECORD
CVE-2026-92243
Ivory Search – WordPress Search Plugin
Reporter: SECURITY
6.1
MEDIUM
VIEW RECORD
CVE-2026-92538
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
Reporter: SECURITY
6.1
MEDIUM
VIEW RECORD
CVE-2026-92551
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
6.1
MEDIUM
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.