Description
The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review display settings have never been saved.
Published: 2026-10-03
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Denial-of-Service caused by uncontrolled resource usage (CWE-400). The WP Ultimate Review WordPress plugin stores review content without validating or sanitizing input from unauthenticated users. A crafted review can be saved when the plugin’s display settings have never been set, causing most pages that invoke the review shortcode to trigger a fatal error on every visit. The resulting error stops the page from rendering, effectively denying service to all visitors.

Affected Systems

Any WordPress site that uses the WP Ultimate Review plugin and has a version earlier than 2.4.4 is affected. Sites that have not yet configured the review display settings are especially vulnerable because the stored content activates the fault on initial load.

Risk and Exploitability

The vulnerability is exploitable by anyone on the internet without needing to authenticate, acting through the standard review submission form. While a CVSS vector is not provided, the impact is a persistent denial of service that cannot be resolved without patching or disabling the plugin. The absence of an EPSS score and no listing in the KEV catalog suggests that widespread exploitation has not yet been observed, but the logical simplicity of the attack means it could proliferate quickly.

Generated by OpenCVE AI on October 3, 2026 at 07:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Ultimate Review to version 2.4.4 or later
  • If an upgrade cannot be performed immediately, disable or uninstall the WP Ultimate Review plugin to stop the faulty review processing
  • Deploy a web application firewall rule that blocks requests containing malicious review payloads or narrows review submission to authenticated users only

Generated by OpenCVE AI on October 3, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review display settings have never been saved.
Title WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T06:00:24.612Z

Reserved: 2026-09-28T08:45:42.950Z

Link: CVE-2026-101161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:38.590

Modified: 2026-10-03T06:16:38.590

Link: CVE-2026-101161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:00:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption