Description
The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.
Published: 2026-10-03
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The WP Ultimate Review WordPress plugin, in versions older than 2.4.4, does not escape the content of certain review overview settings before rendering them within posts. This oversight allows any user with an author role to store malicious JavaScript in those setting fields. When the affected post is viewed, the script is executed in the visitor's browser, giving the attacker the ability to hijack sessions, steal credentials, or deliver arbitrary content to any site visitor.

Affected Systems

All WordPress sites that have installed WP Ultimate Review before version 2.4.4 and have author reviews enabled are susceptible. Sites that have disabled this feature or are running a newer, patched version of the plugin are not affected.

Risk and Exploitability

The vulnerability requires only author‑level access, a role that is commonly present on WordPress installations, which lowers the barrier for exploitation. The CVSS score of 6.4 classifies it as moderate severity, and the EPSS score of <1% suggests that mass exploitation is currently unlikely, though the issue is not listed in the CISA KEV catalog. Despite the low likelihood of widespread attacks, the low privilege requirement and the potential impact on all visitors to affected posts make this a notable risk for administrators.

Generated by OpenCVE AI on October 3, 2026 at 17:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Ultimate Review to version 2.4.4 or later if available from the vendor.
  • If an upgrade is not possible, disable author reviews or the specific review overview settings that accept unsanitized input to prevent malicious script storage.
  • Remove the WP Ultimate Review plugin entirely if no mitigation is feasible and replace it with another plugin that properly sanitizes user input.

Generated by OpenCVE AI on October 3, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.
Title WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:22.965Z

Reserved: 2026-09-28T08:45:44.250Z

Link: CVE-2026-101162

cve-icon Vulnrichment

Updated: 2026-10-03T15:06:47.147Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:38.893

Modified: 2026-10-03T16:16:31.863

Link: CVE-2026-101162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T18:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')