CyberRota Analysis
AI-GeneratedUnauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce versions up to 1.2.30 allow attackers to access and manipulate sensitive data without proper authorization. This vulnerability poses a high risk as it can lead to unauthorized data exposure or modification, potentially compromising user privacy and trust. E-commerce platforms using affected versions should prioritize patching this vulnerability to safeguard customer data and maintain compliance.
CVE
CVE-2026-100517
Severity
HIGH
CVSS
7.5
EPSS
0.30%
Original NVD Description
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.