Impact
The WP Ultimate Review WordPress plugin, in versions older than 2.4.4, does not escape the content of certain review overview settings before rendering them within posts. This oversight allows any user with an author role to store malicious JavaScript in those setting fields. When the affected post is viewed, the script is executed in the visitor's browser, giving the attacker the ability to hijack sessions, steal credentials, or deliver arbitrary content to any site visitor.
Affected Systems
All WordPress sites that have installed WP Ultimate Review before version 2.4.4 and have author reviews enabled are susceptible. Sites that have disabled this feature or are running a newer, patched version of the plugin are not affected.
Risk and Exploitability
The vulnerability requires only author‑level access, a role that is commonly present on WordPress installations, which lowers the barrier for exploitation. The CVSS score of 6.4 classifies it as moderate severity, and the EPSS score of <1% suggests that mass exploitation is currently unlikely, though the issue is not listed in the CISA KEV catalog. Despite the low likelihood of widespread attacks, the low privilege requirement and the potential impact on all visitors to affected posts make this a notable risk for administrators.
OpenCVE Enrichment