Impact
The WP Ultimate Review plugin for WordPress contains an arbitrary shortcode execution flaw that permits unauthenticated users to inject and run any shortcode. The vulnerability arises because the plugin fails to validate input before passing it to WordPress's do_shortcode function. An attacker can therefore execute malicious shortcodes that may load arbitrary code, access files, alter database entries, or otherwise compromise the site's integrity and confidentiality. This flaw is classified as CWE‑94, which represents code injection vulnerabilities.
Affected Systems
The flaw affects all WordPress sites that have the WP Ultimate Review plugin installed, specifically versions up to and including 2.4.3. Site administrators should review their WordPress installations for the presence of this plugin and check the installed version against the stated vulnerable releases.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 corresponds to a medium severity, and the EPSS score is not available, so the exploitation probability cannot be quantified. The issue is not listed in CISA’s KEV catalog. Because the nonce used as a gate is emitted in the public review form and is automatically accepted, an unauthenticated attacker can trigger the vulnerability simply by submitting a crafted review from any location that has access to the public form. No account or privileged action is required, making this a straightforward exploitation path for attackers who wish to run arbitrary code on the site.
OpenCVE Enrichment