CVE-2026-3355 — Cross-Site Scripting (XSS)

CVE-2026-3355 — Cross-Site Scripting (XSS)

Image via images.unsplash.com

CVE-2026-3355 — The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated

Indicators of Compromise

IDTypeIndicator
CVE-2026-3355 vulnerability CVE-2026-3355
CWE-79 weakness CWE-79
🔎
Turn this CVE into SIEM detection coverage Generate detection rules for Splunk, Sentinel, QRadar & Elastic — straight from this vulnerability. Use /detect in the Intel Bot.
Open Intel Bot →
Source & Attribution
Source PlatformNVD
ChannelNational Vulnerability Database
PublishedApril 16, 2026 at 10:16 UTC

This content was curated and summarized by Shimi's Cyber World for informational purposes. It is not copied or republished in full. All intellectual property rights remain with the original author and source.

Believe this infringes your rights? Submit a takedown request.

Related Posts

Dell Storage Manager Flaw: Local Privilege Escalation Risk

CVE-2026-23772 — Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local...

vulnerabilityCVEhigh-severitycwe-269
/HIGH /⚑ 3 IOCs

WSO2 XML Parsers Vulnerable to External Entity Attacks

CVE-2024-2374 — The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission...

vulnerabilityCVEhigh-severitydenial-of-servicecwe-611
/HIGH /⚑ 5 IOCs

AI Agents Vulnerable to 'Comment and Control' Prompt Injection

A new AI attack method, dubbed 'Comment and Control,' has been detailed by a researcher, according to SecurityWeek. This technique exploits vulnerabilities in leading AI...

threat-intelvulnerabilityai-securitytools
/MEDIUM /⚑ 4 IOCs