PT-2026-53811 · WordPress · Editorial Rating – Product Review & Rating System

·

CVE-2026-12560

·

Published

2026-06-30

·

Updated

2026-07-09

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Editorial Rating – Product Review & Rating System versions prior to 4.0.6
Description Insufficient input sanitization and output escaping allow authenticated attackers with administrator-level access and above to perform Stored Cross-Site Scripting. This is achieved by injecting arbitrary web scripts through the 'Link URL' field, which are then stored in the post meta wpas er options via the update post meta() function. These scripts execute whenever a user accesses the affected page. This issue bypasses the standard WordPress unfiltered html capability exemption because the payload is stored in post metadata rather than the main post content or excerpt.
Recommendations Update Editorial Rating – Product Review & Rating System to version 4.0.6 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12560

Affected Products

Editorial Rating – Product Review & Rating System