Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jtibbles WP Ultimate Reviews FREE wp-ultimate-reviews-free allows Reflected XSS.This issue affects WP Ultimate Reviews FREE: from n/a through <= 1.0.2.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an instance of Improper Neutralization of Input During Web Page Generation, allowing attackers to inject malicious script content that is reflected back to the victim’s browser. The injected script can perform a range of malicious actions including cookie theft, session hijacking, or executing arbitrary client‑side code. The issue is classified as CWE‑79 and carries a CVSS score of 7.1, signifying a moderate–to–high potential for exploitation when properly delivered.

Affected Systems

The flaw impacts the WP Ultimate Reviews FREE plugin developed by jtibbles, affecting all installations that use that plugin at any version prior to or equal to 1.0.2. WordPress sites that have this plugin enabled are therefore vulnerable.

Risk and Exploitability

The exploit probability is low, with an EPSS score listed as <1% and the vulnerability not yet being tracked in CISA’s KEV catalogue. The likely attack vector is a victim‑side attack in which an attacker crafts a malicious URL containing script payloads that are reflected by the plugin’s review processing logic; the attacker does not need privileged access or authentication to succeed. Due to the client‑side nature of the attack, damage is limited to the victim’s browser but can still lead to credential theft or defacement of the page.

Generated by OpenCVE AI on May 1, 2026 at 14:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Ultimate Reviews FREE plugin to the latest version or remove it if unused
  • If you cannot update immediately, disable or sanitize review input fields to eliminate untrusted data
  • Implement a web application firewall rule that blocks suspicious query parameters or scripts associated with reflected XSS

Generated by OpenCVE AI on May 1, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5681 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Ultimate Reviews FREE allows Reflected XSS. This issue affects WP Ultimate Reviews FREE: from n/a through 1.0.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Ultimate Reviews FREE allows Reflected XSS. This issue affects WP Ultimate Reviews FREE: from n/a through 1.0.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jtibbles WP Ultimate Reviews FREE wp-ultimate-reviews-free allows Reflected XSS.This issue affects WP Ultimate Reviews FREE: from n/a through <= 1.0.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Ultimate Reviews FREE allows Reflected XSS. This issue affects WP Ultimate Reviews FREE: from n/a through 1.0.2.
Title WordPress WP Ultimate Reviews FREE plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:18.372Z

Reserved: 2025-01-16T11:29:21.051Z

Link: CVE-2025-23739

cve-icon Vulnrichment

Updated: 2025-03-04T20:27:36.628Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:46.300

Modified: 2026-06-17T08:56:49.177

Link: CVE-2025-23739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')