📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h Global vulnerability Artificial Intelligence and Technology HIGH 3h Global general Technology and Artificial Intelligence MEDIUM 6h Global general Technology and Artificial Intelligence HIGH 7h Global vulnerability Higher Education CRITICAL 16h Global data_breach Government HIGH 17h Global supply_chain Software Development and Open Source Communities CRITICAL 17h Global malware Software Development CRITICAL 17h Global phishing Multiple Sectors HIGH 18h Global vulnerability Web Applications CRITICAL 18h Global apt Critical Infrastructure CRITICAL 18h
Vulnerabilities

CVE-2026-4664

Medium
CWE-287 — Weakness Type
Published: Apr 10, 2026  ·  Modified: Apr 13, 2026  ·  Source: NVD
CVSS v3
5.3
🔗 NVD Official
📄 Description (English)

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict equality (`===`), without verifying that the stored key is non-empty. For orders where no review reminder email has been sent, the `ivole_secret_key` meta is not set, causing `get_meta()` to return an empty string. An attacker can supply `key: ""` to match this empty value and bypass the permission check. This makes it possible for unauthenticated attackers to submit, modify, and inject product reviews on any product — including products not associated with the referenced order — via the REST API endpoint `POST /ivole/v1/review`. Reviews are auto-approved by default since `ivole_enable_moderation` defaults to `"no"`.

🤖 AI Executive Summary

The Customer Reviews for WooCommerce plugin contains an authentication bypass vulnerability in versions up to 5.103.0 that allows unauthenticated attackers to submit and modify product reviews via the REST API. The flaw exists in the create_review_permissions_check() function which fails to validate that stored secret keys are non-empty before comparison.

📄 Description (Arabic)

يؤثر هذا الضعف على جميع إصدارات مكون Customer Reviews for WooCommerce حتى 5.103.0 ويسمح للمهاجمين بتجاوز فحوصات الأذونات بتقديم مفتاح فارغ. يمكن للمهاجمين تقديم وتعديل التقييمات على أي منتج بما في ذلك المنتجات غير المرتبطة بالطلب المرجعي عبر نقطة نهاية REST API. التقييمات يتم الموافقة عليها تلقائياً بشكل افتراضي مما يزيد من تأثير الهجوم.

🤖 ملخص تنفيذي (AI)

عرضة لثغرة تجاوز المصادقة في مكون Customer Reviews for WooCommerce حتى الإصدار 5.103.0 يسمح للمهاجمين غير المصرح لهم بتقديم وتعديل تقييمات المنتجات عبر واجهة REST API. يحدث الخلل في دالة create_review_permissions_check() التي تفشل في التحقق من أن مفاتيح السر المخزنة غير فارغة قبل المقارنة.

🤖 AI Intelligence Analysis Analyzed: May 29, 2026 09:43
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
banking telecom energy government healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
7.0
/ 10.0
🔧 Remediation Steps (English)
Update the Customer Reviews for WooCommerce plugin to version 5.103.1 or later immediately. Additionally, implement input validation to ensure the ivole_secret_key meta value is non-empty before performing strict equality comparisons. Review and audit all product reviews submitted during the vulnerability window for unauthorized or malicious content.
🔧 خطوات المعالجة (العربية)
قم بتحديث مكون Customer Reviews for WooCommerce إلى الإصدار 5.103.1 أو أحدث على الفور. بالإضافة إلى ذلك، قم بتنفيذ التحقق من صحة الإدخال للتأكد من أن قيمة ivole_secret_key غير فارغة قبل إجراء مقارنات المساواة الصارمة. راجع وتدقيق جميع تقييمات المنتجات المقدمة أثناء نافذة الثغرة للبحث عن محتوى غير مصرح به أو ضار.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 5.1.2 5.2.1
🔵 SAMA CSF
AC-2 AC-3 AC-6
🟡 ISO 27001:2022
A.9.1.1 A.9.2.1 A.9.4.3
📊 CVSS Score
5.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score5.3
CWECWE-287
EPSS0.18%
Exploit No
Patch ✗ No
Published 2026-04-10
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
7.0
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-287
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.