PT-2026-99243 · WordPress · Wp Review Slider Pro

·

CVE-2026-84096

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wp-review-slider-pro versions prior to 12.7.12
Description The plugin fails to perform a capability check on the AJAX handler used to save review submission forms. Additionally, the nonce (a unique token used to prevent replay attacks) is generated for every visitor. This allows any authenticated user, including those with subscriber-level privileges, to overwrite a live form with field values. Because these values are output on public pages without proper escaping, it leads to Stored Cross-Site Scripting (XSS), where malicious scripts are permanently stored on the server and executed in the browsers of other users.
Recommendations Update wp-review-slider-pro to version 12.7.12 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84096

Affected Products

Wp Review Slider Pro