WordPress · Editorial Rating – Product Review & Rating System · CVE-2026-12560
**Name of the Vulnerable Software and Affected Versions**
Editorial Rating – Product Review & Rating System versions prior to 4.0.6
**Description**
Insufficient input sanitization and output escaping allow authenticated attackers with administrator-level access and above to perform Stored Cross-Site Scripting. This is achieved by injecting arbitrary web scripts through the 'Link URL' field, which are then stored in the post meta ` wpas er options` via the `update post meta()` function. These scripts execute whenever a user accesses the affected page. This issue bypasses the standard WordPress `unfiltered html` capability exemption because the payload is stored in post metadata rather than the main post content or excerpt.
**Recommendations**
Update Editorial Rating – Product Review & Rating System to version 4.0.6 or later.