Description
The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.
Published: 2026-10-03
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because the WP Ultimate Review plugin does not validate that a submitted review rating is a number before storing it. When a non‑numeric rating is stored, later numeric operations used during review rendering trigger a fatal error. This causes all users viewing reviews to see a crash, resulting in a persistent denial of service for the site’s content that includes reviews. The weakness corresponds to improper input validation, allowing an attacker to inject non‑numeric data that leads to a crash.

Affected Systems

WordPress sites employing the WP Ultimate Review plugin version earlier than 2.4.4 are affected when user reviews are enabled. The plugin is listed by CNAs as "Unknown:WP Ultimate Review." No other vendors or product variants are indicated.

Risk and Exploitability

The vulnerability is exploitable by unauthenticated users who can post a review with a non‑numeric rating. Because the plugin treats the rating as a numeric value during rendering, this can be triggered with any publicly reachable WordPress site that has the plugin installed and reviews enabled. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The severity is high due to the denial‑of‑service impact and the lack of authentication requirement, but an exact CVSS score is not supplied. Attackers can amplify impact by repeatedly posting malicious reviews, leading to sustained service unavailability until the offending reviews are manually removed.

Generated by OpenCVE AI on October 3, 2026 at 07:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Ultimate Review to version 2.4.4 or later to obtain the numeric‑rating validation fix.
  • If an upgrade is not possible, disable the 'user reviews' feature in the plugin settings to eliminate the vector for creating malicious ratings.
  • Remove any existing reviews containing non‑numeric ratings to stop the fatal error. Monitor the site for unexpected crashes.

Generated by OpenCVE AI on October 3, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.
Title WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T06:00:24.431Z

Reserved: 2026-09-28T08:45:41.583Z

Link: CVE-2026-101160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:38.350

Modified: 2026-10-03T06:16:38.350

Link: CVE-2026-101160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:00:16Z

Weaknesses
  • CWE-20

    Improper Input Validation