OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100515

HIGH · CVSS 7.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability in VillaTheme Photo Reviews for WooCommerce allows for reflected cross-site scripting (XSS) due to improper input neutralization during web page generation. This can enable attackers to execute arbitrary scripts in the context of a user's browser, potentially leading to data theft or session hijacking. Users of Photo Reviews for WooCommerce versions up to 1.2.30 should prioritize patching this issue to mitigate the risk.

CVE
CVE-2026-100515
Severity
HIGH
CVSS
7.1
EPSS
0.19%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30.