PT-2026-99242 · WordPress · Wp Review Slider Pro

·

CVE-2026-84095

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wp-review-slider-pro versions prior to 12.7.12
Description An issue exists where an AJAX handler fails to perform a capability check. Because the nonce protecting this handler is generated for every visitor, any authenticated user, including those with subscriber privileges, can store arbitrary review content. This content is subsequently rendered on public pages without proper escaping, resulting in Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server and executed in the browsers of other users.
Recommendations Update wp-review-slider-pro to version 12.7.12 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84095

Affected Products

Wp Review Slider Pro