Impact
Denial-of-Service caused by uncontrolled resource usage (CWE-400). The WP Ultimate Review WordPress plugin stores review content without validating or sanitizing input from unauthenticated users. A crafted review can be saved when the plugin’s display settings have never been set, causing most pages that invoke the review shortcode to trigger a fatal error on every visit. The resulting error stops the page from rendering, effectively denying service to all visitors.
Affected Systems
Any WordPress site that uses the WP Ultimate Review plugin and has a version earlier than 2.4.4 is affected. Sites that have not yet configured the review display settings are especially vulnerable because the stored content activates the fault on initial load.
Risk and Exploitability
The vulnerability is exploitable by anyone on the internet without needing to authenticate, acting through the standard review submission form. While a CVSS vector is not provided, the impact is a persistent denial of service that cannot be resolved without patching or disabling the plugin. The absence of an EPSS score and no listing in the KEV catalog suggests that widespread exploitation has not yet been observed, but the logical simplicity of the attack means it could proliferate quickly.
OpenCVE Enrichment