Impact
The Wp Ultimate Review plugin contains a DOM‑based XSS flaw caused by insufficient input sanitization in the web interface. An attacker that can submit or influence content stored by the plugin can trigger the execution of arbitrary JavaScript in the browsers of users who view the affected pages. This may lead to session hijacking, credential theft, or defacement of the site. The weakness is a typical Cross‑Site Scripting vulnerability (CWE‑79). The description does not detail authentication requirements, so the likely attack vector is user‑controlled input via the plugin’s front‑end components.
Affected Systems
Roxnor’s Wp Ultimate Review WordPress plugin, versions up to and including 2.3.7, is affected. Any WordPress installation running this plugin in those versions is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% reflects a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The primary attack path involves submitting malicious input through the plugin’s front‑end components, suggesting that any user with permission to create or edit review content could exploit the flaw. While the impact is limited to the affected visitor’s browser, the potential for credential theft or session hijacking warrants timely remediation.
OpenCVE Enrichment