Sceawere

Vulnerability Detail

CVE-2026-101159UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Ultimate Review Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
13h ago
Vendor
Unknown
Product
WP Ultimate Review
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-03T06:16:38.023Z",
  "pubdate": "2026-10-03T06:16:38.023Z",
  "executiveSummary": "The WP Ultimate Review WordPress plugin prior to version 2.4.4 contains a Stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from the failure to properly sanitize and escape input submitted through the plugin's public review form.\nThis vulnerability allows unauthenticated remote attackers to inject arbitrary malicious JavaScript or HTML into review content. When a victim, such as an administrator, views a page where the malicious review is rendered, the payload executes within the context of their session.\nThe impact is significant, potentially leading to unauthorized actions performed on behalf of the victim, session hijacking, credential theft, or the redirection of users to malicious websites. Because the vulnerability is exploitable by unauthenticated users via a public-facing form, it poses a high risk to the integrity and security of the WordPress installation.\nThe vulnerability is inherent in the handling of user-contributed content within the plugin. To mitigate this threat, users must upgrade to version 2.4.4 or later.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS) due to the plugin's failure to implement robust output encoding or input sanitization on user-provided review data. Specifically, the plugin's review submission mechanism accepts arbitrary input from unauthenticated visitors without validating the content for executable scripts or malicious markup.\nRoot Cause Analysis: The core of the vulnerability resides in the backend processing logic that handles data submitted via the public review form. The plugin accepts this input and stores it directly into the WordPress database without applying necessary sanitization functions (such as sanitize_text_field or wp_kses) or ensuring context-aware output escaping when the review is retrieved and rendered on the frontend.\nAttack Flow: 1. An unauthenticated attacker interacts with the public-facing review form provided by the WP Ultimate Review plugin. 2. The attacker inputs a crafted payload containing malicious JavaScript (e.g., <script>alert('XSS')</script>) into one of the review fields. 3. The plugin processes the submission and persists the malicious payload into the WordPress database associated with the review post. 4. When an authorized user, such as an administrator or editor, navigates to the page displaying these reviews, the plugin retrieves the stored data from the database. 5. The malicious script is then echoed into the HTML document of the victim's browser without proper escaping. 6. The victim's browser executes the script within the origin of the WordPress site.\nPayload Behavior: The injected payload executes within the security context of the victim's session. This grants the attacker the ability to perform any action the victim is authorized to perform, access sensitive session cookies (if not protected by HttpOnly flags), manipulate the DOM, or exfiltrate sensitive data to an external server controlled by the attacker.\nAffected Versions: All versions of the WP Ultimate Review plugin prior to 2.4.4 are susceptible to this flaw. The attack requires no authentication and is accessible over the network via the web interface. Successful exploitation results in persistent compromise of the user session, as the malicious code remains stored in the database until manually removed or the plugin is patched and the database cleaned."
}
CVE-2026-101159: WP Ultimate Review Stored XSS (HIGH Severity, CVSS: 7.5) | Sceawere