AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14941

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Customer Reviews for WooCommerce plugin for WordPress prior to version 5.116.0 is vulnerable due to a lack of nonce and capability checks on certain AJAX actions, enabling users with minimal permissions, like Subscribers, to access and modify administrative settings. This could lead to unauthorized changes in plugin options and potential exposure of sensitive store configuration data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-14941
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
WordPress

Original NVD Description

The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.