Description
The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction.
Published: 2026-10-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Patch Now
AI Analysis

Impact

The WP Ultimate Review plugin for WordPress contains an arbitrary shortcode execution flaw that permits unauthenticated users to inject and run any shortcode. The vulnerability arises because the plugin fails to validate input before passing it to WordPress's do_shortcode function. An attacker can therefore execute malicious shortcodes that may load arbitrary code, access files, alter database entries, or otherwise compromise the site's integrity and confidentiality. This flaw is classified as CWE‑94, which represents code injection vulnerabilities.

Affected Systems

The flaw affects all WordPress sites that have the WP Ultimate Review plugin installed, specifically versions up to and including 2.4.3. Site administrators should review their WordPress installations for the presence of this plugin and check the installed version against the stated vulnerable releases.

Risk and Exploitability

The CVSS v3.1 base score of 6.5 corresponds to a medium severity, and the EPSS score is not available, so the exploitation probability cannot be quantified. The issue is not listed in CISA’s KEV catalog. Because the nonce used as a gate is emitted in the public review form and is automatically accepted, an unauthenticated attacker can trigger the vulnerability simply by submitting a crafted review from any location that has access to the public form. No account or privileged action is required, making this a straightforward exploitation path for attackers who wish to run arbitrary code on the site.

Generated by OpenCVE AI on October 3, 2026 at 08:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the WP Ultimate Review plugin to the latest release, which includes a fix for the arbitrary shortcode execution bug.
  • If an immediate update is not feasible, disable or restrict access to the public review form so that the exposed nonce is no longer available to unauthenticated users.
  • As a temporary safeguard, remove the WP Ultimate Review plugin or configure WordPress to strip or block shortcodes injected through user‑generated content until a patch is applied.

Generated by OpenCVE AI on October 3, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction.
Title WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter (Split-Shortcode / Late-Registered Shortcode)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:41.054Z

Reserved: 2026-09-25T12:18:04.662Z

Link: CVE-2026-100157

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:36.519Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:46.330

Modified: 2026-10-03T16:16:30.890

Link: CVE-2026-100157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:30:18Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')