We recently discovered the WP Customer Reviews plugin had a cross-site request forgery (CSRF) vulnerability. In version 3.0.8, and some prior versions, the plugin did not insure that actions, including deleting the all of the reviews created in the plugin, were actually made by the requested user with a nonce.
Proof Of Concept
The following proof of concept will delete all of the plugin’s reviews. [Read more]