CVE-2026-11608

CVE-2026-11608 published: The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for u...

View full NVD advisory → ← Back to CVE watch