Description
The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.
Published: 2026-10-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The WP Ultimate Review WordPress plugin before version 2.4.4 does not sanitize or escape review text submitted through its public review form. An unauthenticated visitor can embed malicious JavaScript that is stored in the database and eventually executed in any browser that loads a review‑enabled page. This stored XSS vulnerability could allow attackers to steal user session cookies, deface content, or redirect victims to phishing sites, compromising confidentiality, integrity, and availability of the site’s users, including administrators.

Affected Systems

WordPress sites that use the WP Ultimate Review plugin with a version earlier than 2.4.4. Any instance that has the public review form enabled and reviews displayed would be affected. The plugin vendor is unknown; the vulnerability is present in all installations of this plugin that have not been upgraded to the patched release.

Risk and Exploitability

The CVSS score is 7.5, the EPSS score is <1%, and it is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated POST request to the review submission endpoint, meaning a remote attacker can create a review that contains malicious script. Since the flaw resides in server‑side data storage and rendering, no additional access privileges or elevated permissions are required to exploit, making the vulnerability highly actionable for any internet‑accessible site that has the review form open.

Generated by OpenCVE AI on October 3, 2026 at 17:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WP Ultimate Review plugin to version 2.4.4 or later, which implements proper sanitisation and escaping of user input.
  • If an upgrade is not immediately possible, disable the public review submission form or restrict it to authenticated users only to prevent unauthenticated submissions from being stored.
  • Apply a security plugin or web‑application firewall rule that blocks JavaScript payloads in POST fields with the review submission form to mitigate the risk of stored XSS.

Generated by OpenCVE AI on October 3, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.
Title WP Ultimate Review < 2.4.4 - Unauthenticated Stored XSS via Review Submission
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:23.401Z

Reserved: 2026-09-28T08:45:39.902Z

Link: CVE-2026-101159

cve-icon Vulnrichment

Updated: 2026-10-03T15:07:14.912Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:38.023

Modified: 2026-10-03T16:16:31.397

Link: CVE-2026-101159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T17:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')