PT-2026-99242 · WordPress · Wp Review Slider Pro
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wp-review-slider-pro versions prior to 12.7.12
Description
An issue exists where an AJAX handler fails to perform a capability check. Because the nonce protecting this handler is generated for every visitor, any authenticated user, including those with subscriber privileges, can store arbitrary review content. This content is subsequently rendered on public pages without proper escaping, resulting in Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server and executed in the browsers of other users.
Recommendations
Update wp-review-slider-pro to version 12.7.12 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Review Slider Pro