Impact
WP Ultimate Review allows authenticated users with subscriber or higher privileges to inject and execute shortcodes that bypass validation by using the xs_review_summery parameter. The plugin removes disallowed double‑bracket escapes, leaving standard single‑bracket tags which are then processed by WordPress when the review post is rendered. This flaw, classified as CWE‑94, means an attacker can run arbitrary shortcode payloads, including possibly malicious PHP code, leading to code execution, data theft, or site takeover.
Affected Systems
Any WordPress site running WP Ultimate Review versions 2.4.3 or earlier is affected. The vendor, roxnor, distributes the plugin under the name WP Ultimate Review. Sites that have not upgraded past version 2.4.3 are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Since EPSS is not available, the likelihood of exploitation in the wild is unknown, but the attack requires only a legitimate subscriber account, which is common on many sites. The flaw permits arbitrary code execution through a content injection path, so the potential impact is high if an attacker can gain the necessary access.
OpenCVE Enrichment