Description
The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The bypass relies on WordPress's own strip_shortcodes() function unwrapping the [[tag]] double-bracket escape to a bare [tag] that survives wp_insert_post storage and fires when the publicly queryable xs_review post type is rendered through the_content.
Published: 2026-10-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

WP Ultimate Review allows authenticated users with subscriber or higher privileges to inject and execute shortcodes that bypass validation by using the xs_review_summery parameter. The plugin removes disallowed double‑bracket escapes, leaving standard single‑bracket tags which are then processed by WordPress when the review post is rendered. This flaw, classified as CWE‑94, means an attacker can run arbitrary shortcode payloads, including possibly malicious PHP code, leading to code execution, data theft, or site takeover.

Affected Systems

Any WordPress site running WP Ultimate Review versions 2.4.3 or earlier is affected. The vendor, roxnor, distributes the plugin under the name WP Ultimate Review. Sites that have not upgraded past version 2.4.3 are at risk.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Since EPSS is not available, the likelihood of exploitation in the wild is unknown, but the attack requires only a legitimate subscriber account, which is common on many sites. The flaw permits arbitrary code execution through a content injection path, so the potential impact is high if an attacker can gain the necessary access.

Generated by OpenCVE AI on October 3, 2026 at 08:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Ultimate Review to version 2.4.4 or later.
  • Restrict or remove the ability for subscriber‑level users to edit or create review posts that use the xs_review_summery field, such as by adjusting role capabilities or using a capability‑management plugin.
  • Disable the xs_review custom post type or the content rendering that triggers do_shortcode for untrusted posts until a patch is applied.

Generated by OpenCVE AI on October 3, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The bypass relies on WordPress's own strip_shortcodes() function unwrapping the [[tag]] double-bracket escape to a bare [tag] that survives wp_insert_post storage and fires when the publicly queryable xs_review post type is rendered through the_content.
Title WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:41.904Z

Reserved: 2026-09-30T19:01:44.804Z

Link: CVE-2026-103519

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:45.835Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:47.050

Modified: 2026-10-03T16:16:33.287

Link: CVE-2026-103519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:30:18Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')