Sceawere

Vulnerability Detail

CVE-2026-100157UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Ultimate Review Shortcode Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
roxnor
Product
WP Ultimate Review
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-03T07:16:46.330Z",
  "pubdate": "2026-10-03T07:16:46.330Z",
  "executiveSummary": "The WP Ultimate Review plugin for WordPress contains a critical arbitrary shortcode execution vulnerability affecting all versions up to and including 2.4.3. This security flaw stems from improper input validation within a publicly accessible plugin action, allowing unauthenticated remote attackers to execute arbitrary shortcodes on the target site.\nThe vulnerability is characterized by the insecure use of the do_shortcode function on user-supplied data. Exploitation is facilitated by the fact that the required security nonce is publicly exposed in the plugin's frontend review form, effectively neutralizing the intended authorization check. Furthermore, submitted payloads are auto-published by default, bypassing the need for administrative approval.\nThe impact of this vulnerability is severe, as it permits unauthenticated actors to trigger arbitrary shortcodes, potentially leading to unauthorized data exposure, content modification, or remote code execution depending on the shortcodes available within the WordPress environment. Given that no authentication or elevated privileges are required, this vulnerability represents a significant risk to the integrity and confidentiality of the affected WordPress installation.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper handling of user-supplied input during the processing of a specific plugin action. The plugin utilizes the WordPress do_shortcode function on data submitted via an unauthenticated form without performing adequate validation or sanitization. This allows an attacker to inject malicious shortcode payloads that the underlying WordPress engine will parse and execute during the request lifecycle.\nThe exploit chain begins with the attacker accessing the plugin's public review form, where a security nonce is exposed to all visitors. This nonce is the only gatekeeper for the vulnerable action, and its exposure renders the security check ineffective. An attacker can scrape this nonce from the frontend and include it in a crafted HTTP POST request directed at the vulnerable endpoint.\nUpon receiving the request, the plugin validates the provided nonce, which passes due to its previous exposure. The plugin then processes the submitted input—which contains the malicious shortcode—and triggers the do_shortcode function. Because the plugin is configured to auto-publish submissions by default, these malicious payloads are immediately rendered and executed without requiring prior authorization or interaction from an administrative user.\nThis vulnerability is present in all versions up to and including 2.4.3 of the WP Ultimate Review plugin. The exposure is entirely network-based, meaning any unauthenticated attacker with access to the public-facing WordPress site can execute the attack. The technical impact is significant; by leveraging arbitrary shortcodes, an attacker can manipulate page content, potentially retrieve sensitive information from the database, or trigger other plugin-specific functionalities that were not intended to be exposed to public users.\nThe post-exploitation phase depends heavily on the ecosystem of available shortcodes installed on the target system. In many WordPress environments, third-party plugins or themes provide shortcodes that can perform advanced operations. By successfully injecting these, an attacker moves from an initial injection vector to the execution of arbitrary application-level logic, which can result in full site compromise."
}
CVE-2026-100157: WP Ultimate Review Shortcode Injection (MEDIUM Severity, CVSS: 6.5) | Sceawere