External risk intelligence

Customer Reviews for WooCommerce Plugin Allows Unauthorized Attachment Deletion

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-89055

The vulnerability exists in a WooCommerce plugin for WordPress, which is commonly deployed as an internet-facing web application. The affected functionality is exposed via a public-facing review form intended for customer interaction, making the vulnerable endpoint reachable by remote, unauthenticated users over the public internet in standard deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in a WordPress plugin that allows for permanent deletion of website content. This issue, stemming from improper authorization checks, enables unauthenticated attackers to remove various attachments, such as product images or logos, by exploiting a public review form. The main concern is confirming if this plugin is in use and if such content is exposed.

  • Unauthenticated attackers can delete arbitrary website files.
  • Critical content loss is possible; verify plugin usage.
  • Confirm exposure and assess impact on business assets.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by leveraging a public review form link to bypass authorization checks. This allows them to submit review data containing crafted IDs, which, when later processed for deletion, results in the permanent removal of arbitrary files from the website's media library.

  • Public review form link is accessible.
  • Attacker crafts review with attachment IDs.
  • Arbitrary file deletion occurs.

Live Threat

Current exploitation, exposure, and threat context

The Customer Reviews for WooCommerce plugin's authorization bypass vulnerability could allow unauthenticated attackers to delete any attachment from the WordPress Media Library. This risk exists when a public review form link is accessible, enabling the attacker to inject attachment IDs into a review that is later purged.

  • Arbitrary attachments in Media Library.
  • Unauthenticated deletion via public review form.
  • Permanent loss of administrator-owned content.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Customer Reviews for WooCommerce plugin on WordPress sites is vulnerable, allowing unauthenticated attackers to delete arbitrary attachments. Action is required by the website owner or platform administrator responsible for managing WordPress plugins and their associated media library. The initial step involves identifying all instances of the affected plugin, confirming exposure via public review forms, and assessing the business criticality of the stored attachments to prioritize remediation efforts.

  • Website owners and platform administrators own this issue.
  • Verify public review form exposure and critical media.
  • Plan remediation based on confirmed risk and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Customer Reviews for WooCommerce plugin?

This is an add-on for WordPress websites that helps businesses collect feedback from buyers. It automates sending email requests for reviews and manages how those reviews appear on product pages. Because it handles customer interaction, it integrates directly with the site's media system to manage images and documents attached to reviews.

What does CVE-2026-89055 mean for my site?

This vulnerability is classified as an improper authorization flaw, known as CWE-862. Essentially, the software fails to confirm that a user has permission before executing a command. In this case, it allows someone without a login to trigger a cleanup process that permanently deletes files from your site’s media library instead of just removing the review.

How does an attacker trigger this deletion?

The attack relies on accessing a specific review-form link sent to customers. If an attacker gains this link, they can submit data containing specific internal file IDs. The system then treats these as attachments to be purged. Simply browsing the website or clicking standard links will not trigger the bug; it requires manipulating the specific, publicly accessible review form process.

Why is this a risk if my plugin is internet-facing?

According to Halo Surface Signal, this vulnerability is particularly relevant because the plugin is designed to be accessible to the public internet for customer feedback. Since the review forms are reachable by anyone, an unauthenticated user could remotely send requests to delete files, bypassing the need for any administrative account or existing session on your WordPress site.

What should I do to address this issue?

First, verify if your WordPress environment has this plugin installed and active. Check your site configuration to see if you use the review forms feature. Prioritize identifying critical assets in your media library that could be lost. Review your plugin management dashboard to see if an update is available to resolve the authorization check, and consult the official plugin repository for the latest version.

References