OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-100517

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce versions up to 1.2.30 allow attackers to access and manipulate sensitive data without proper authorization. This vulnerability poses a high risk as it can lead to unauthorized data exposure or modification, potentially compromising user privacy and trust. E-commerce platforms using affected versions should prioritize patching this vulnerability to safeguard customer data and maintain compliance.

CVE
CVE-2026-100517
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.