Impact
The WP Ultimate Review WordPress plugin before version 2.4.4 does not sanitize or escape review text submitted through its public review form. An unauthenticated visitor can embed malicious JavaScript that is stored in the database and eventually executed in any browser that loads a review‑enabled page. This stored XSS vulnerability could allow attackers to steal user session cookies, deface content, or redirect victims to phishing sites, compromising confidentiality, integrity, and availability of the site’s users, including administrators.
Affected Systems
WordPress sites that use the WP Ultimate Review plugin with a version earlier than 2.4.4. Any instance that has the public review form enabled and reviews displayed would be affected. The plugin vendor is unknown; the vulnerability is present in all installations of this plugin that have not been upgraded to the patched release.
Risk and Exploitability
The CVSS score is 7.5, the EPSS score is <1%, and it is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated POST request to the review submission endpoint, meaning a remote attacker can create a review that contains malicious script. Since the flaw resides in server‑side data storage and rendering, no additional access privileges or elevated permissions are required to exploit, making the vulnerability highly actionable for any internet‑accessible site that has the review form open.
OpenCVE Enrichment