Go ahead and disable WooCommerce and comment on a post; you can do the same thing because you’re logged in as admin. Admin users are able to post unfiltered content. If you repeat the test logged out, you’ll notice you’re not able to exploit anything.
See this trac ticket from WordPress https://core.trac.wordpress.org/ticket/33402
And this article on make.wordpress https://make.wordpress.org/core/handbook/testing/reporting-security-vulnerabilities/#why-are-some-users-allowed-to-post-unfiltered-html
For future reference, please report security issues responsibly rather than publicly – use https://hackerone.com/automattic
Related Posts:
- WooCommerce showing star rating review instead of text review string
- Woocommerce: custom loop in product tabs breaks reviews tab
- Add starts rating in woocommerce product comment from backend
- Woocommerce API security concerns
- WooCommerce Review Author Hook on Review Submission
- Add button linked to single product page on order detail page
- Testimonials/Reviews for Products
- Which php files, in a WordPress setup, do not need direct web access?
- WooCommerce Webhook Action When a New Product Review was Submitted/Created
- Woocommerce – Add a product to cart programmatically via JS or PHP [closed]
- ( Woocommerce) How to get the user belonging to an order? [closed]
- Get the product list of a given Category ID
- List of JS events in the WooCommerce frontend
- get woocommerce My account page link
- WooCommerce: How to edit the get_price_html
- Get woocommerce product price by id [closed]
- Product categories don’t appear as option to build menu
- WooCommerce Variable Product Price not showing on single product page
- How to override WooCommerce template files?
- Woocommerce add extra field to variation product
- Getting the gallery images from products in woocommerce?
- How to get current product category ID in product archive page
- Get url of product’s images (woocommerce)
- WooCommerce prices location in DB
- Order by rating not works in wp_query
- Woocommerce: How to remove page-title at the home/shop page but not category pages
- Woocommerce show cross sells on singe product page [closed]
- How to add a new endpoint in woocommerce
- Are there any hook or filter when refund is done through admin -woocommerce
- How to check if is in cart page? [closed]
- Display single product attribute value on Shop page (Woocommerce)
- WP/WooCommerce REST API cart/checkout/order [closed]
- how to use wc_create_order with subscription product
- WooCommerce: Webhook disabled on its own
- Share users and WooCommerce memberships between two installations
- Slow Loading Attribute Select – WooCommerce Backend
- WooCommerce: Can’t use wc_get_products for custom REST API endpoints
- How to change or add Woocommerce thank you page URL key content?
- How can I define a custom template for woocommerce [products] shortcode? [closed]
- How to remove an action within a class with extends
- single-product.php template not working for single products [closed]
- Insert variations via woocommerce api [closed]
- WooCommerce get physical store address
- Is it possible to add custom fields to a WooCommerce attribute term? [closed]
- wc_get_template_part( ‘content’, ‘product’ ) | Where is this file located?
- how to get woocommerce product attribute slug
- Correct function to get the user’s latest Woocommerce Subscription?
- Move payment options at checkout in WooCommerce [closed]
- add_filter to modify woocommerce_cart_item_name hyperlink
- Where do the cart details are stored in database?
- How to display product price of the product in loop
- How to disable Woocommerce password recovery and use the default WordPress password reset page?
- Display order items names in WooCommerce admin orders list [closed]
- Is it safe to delete from db orphaned posts i.e. whose post_parent no longer exists?
- Add custom variable to cart content [closed]
- Get product details by url key in WordPress woocommerce
- Get product link
- WooCommerce – Hook after Loading Variation in Admin Edit page?
- How to delete woo commerce order pragmatically? [closed]
- WooCommerce changes lost password reset link
- Process checkout using WC REST API
- How to get rid of the hover zoom in WooCommerce single products
- How do I display certain products via their category on a section of a page using PHP?
- How to turn off WooCommerce user registration and manually create accounts?
- What’s the difference between WC() and $woocommerce
- Display orders instead of woocommerce my account dashboard for logged in users [closed]
- Limit users to one active subscription in WooCommerce Subscriptions? [closed]
- Detect whether a page is a product subcategory page?
- Hidden woocommerce products still showing up in search results [closed]
- Menu not show woocommerce product category
- Orders being sent to wrong admin email in WooCommerce [closed]
- WooCommerce: add different order item meta for each item in order
- Remember page before login page, redirect to that page after login
- Woocommerce 3.1 Add product image to order confirmation email not working
- Where is the “default attribute” values located in the phpMyAdmin in Woocommerce?
- Woocommerce My Account Endpoint – how to get ID parameter from URL?
- Hook and send Woocommerce data after click Place Order button
- Woo-commerce | Disable proceed to checkout button in cart page if total in cart less than 15 [closed]
- Fatal Error when installing woocommerce despite upgrading
- Adding an action within a function that is being called by add_filter
- WooCommerce conditional meta query
- Default woocommerce placeholder image
- How to build a plugin that supports authenticated POST requests to the REST API from external servers?
- Hide certain tags on Product Edit tag cloud
- WooCommerce: Add New Report Tab
- WooCommerce Change Product Global Attribute Value via CRUD for Simple Product [closed]
- How to get values from woocommerce admin input fields?
- Show only geolocated user country into Woocommerce checkout country fields
- Search results don’t show products
- Optimizing Woocommerce order items query
- What is the right hook to use in WooCommerce for handling the post of the sale price?
- Add a custom button with custom link after add to cart for every product
- How to add Woocomrce cart page shipping calculator to my country state list
- When Free shipping is available hide other shipping methods except Local pickup in WooCommerce [closed]
- Programmatically change Payment Methods WooCommerce
- Get WooCommerce Email Classes in Backend
- Use Hooks to Limit One Comment Per User Per Post – Hide Form if Already Commented
- Display WooCommerce size product attribute on shop page
- Woocommerce Multisite Search Mod to archive.php but no pagination
- Extend Woocommerce rest api routes fails