Description
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises because the plugin fails to escape a user‑supplied value before inserting it into an HTML tag. This allows an attacker to embed arbitrary JavaScript that will execute in the browser of any user who loads the crafted page, including administrators. The impact is the ability to hijack sessions, deface sites, or deliver malware, compromising the confidentiality, integrity, and availability of the website's content and the users' interactions.

Affected Systems

This flaw affects the Five Star Restaurant Reviews WordPress plugin versions prior to 2.3.14. Any WordPress installation that has the plugin installed and has not been updated to 2.3.14 or later is potentially vulnerable.

Risk and Exploitability

The flaw is exploitable by unauthenticated attackers via a crafted HTTP request, meaning it can be triggered without login credentials. The exact CVSS score is not provided, but the nature of the flaw suggests a high risk of exploitation. Because no EPSS score is available and the vulnerability is not listed in CISA KEV, the precise exploitation probability is unknown; however, the widespread use of the plugin and lack of input sanitization make it a likely target for attack.

Generated by OpenCVE AI on October 1, 2026 at 07:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Five Star Restaurant Reviews plugin to version 2.3.14 or newer
  • Restrict access to the plugin’s configuration and processed pages to authenticated administrators only
  • Apply a Web Application Firewall rule to block or sanitize XSS payloads targeting the plugin’s vulnerable input

Generated by OpenCVE AI on October 1, 2026 at 07:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.
Title Five Star Restaurant Reviews < 2.3.14 - Reflected XSS
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T10:45:48.797Z

Reserved: 2026-09-16T09:06:39.764Z

Link: CVE-2026-92412

cve-icon Vulnrichment

Updated: 2026-10-01T10:43:03.692Z

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:15.377

Modified: 2026-10-01T11:17:30.053

Link: CVE-2026-92412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T07:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')