PT-2026-104515 · WordPress · Wp Ultimate Review
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Ultimate Review WordPress plugin versions prior to 2.4.4
Description
Insufficient sanitization and escaping of reviews submitted via the public review form allow unauthenticated visitors to execute Stored Cross-Site Scripting (XSS) attacks. This occurs when user reviews are enabled, affecting any user, including administrators, who views a page displaying the malicious review.
Recommendations
Update the plugin to version 2.4.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Ultimate Review