Impact
The vulnerability arises because the WP Ultimate Review plugin does not validate that a submitted review rating is a number before storing it. When a non‑numeric rating is stored, later numeric operations used during review rendering trigger a fatal error. This causes all users viewing reviews to see a crash, resulting in a persistent denial of service for the site’s content that includes reviews. The weakness corresponds to improper input validation, allowing an attacker to inject non‑numeric data that leads to a crash.
Affected Systems
WordPress sites employing the WP Ultimate Review plugin version earlier than 2.4.4 are affected when user reviews are enabled. The plugin is listed by CNAs as "Unknown:WP Ultimate Review." No other vendors or product variants are indicated.
Risk and Exploitability
The vulnerability is exploitable by unauthenticated users who can post a review with a non‑numeric rating. Because the plugin treats the rating as a numeric value during rendering, this can be triggered with any publicly reachable WordPress site that has the plugin installed and reviews enabled. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The severity is high due to the denial‑of‑service impact and the lack of authentication requirement, but an exact CVSS score is not supplied. Attackers can amplify impact by repeatedly posting malicious reviews, leading to sustained service unavailability until the offending reviews are manually removed.
OpenCVE Enrichment