Sceawere
Vulnerability Detail
CVE-2026-101160UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Ultimate Review DoS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- WP Ultimate Review
- Attack Type
- CWE-400 Uncontrolled Resource Consumption
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-03T06:16:38.350Z",
"pubdate": "2026-10-03T06:16:38.350Z",
"executiveSummary": "The WP Ultimate Review WordPress plugin, in versions prior to 2.4.4, contains a vulnerability involving improper input validation of review ratings. This flaw allows unauthenticated remote attackers to trigger a persistent Denial of Service (DoS) condition on affected WordPress sites.\nThe vulnerability originates from the plugin's failure to sanitize or validate the numeric nature of user-submitted rating data before storage. By submitting non-numeric data into the rating field, an attacker can cause the application to crash when performing subsequent arithmetic operations during the rendering of the review. This crash manifests as a fatal PHP error, rendering the specific content or the entire page unreachable for all visitors.\nThe impact is significant, as it results in site unavailability for the targeted content. The attack requires no authentication or special privileges, making it easily exploitable by any visitor with access to the review submission interface. Successful exploitation results in persistent disruption that persists until an administrator manually intervenes to remove the malicious entry from the database.",
"technicalDetails": "The root cause of this vulnerability lies in an insecure implementation of data handling within the WP Ultimate Review plugin. Specifically, the plugin architecture fails to enforce strict input validation regarding the data type of the 'rating' parameter during the POST request submission process. When a user submits a review, the plugin accepts the rating input without verifying that the value is of a numeric data type (e.g., an integer or float).\nDuring the review storage process, this unvalidated input is committed to the database. Subsequently, when the plugin attempts to render the review on the frontend, it retrieves this stored value and processes it using mathematical operators. Because the application logic expects a numeric value but receives non-numeric or malformed input, it triggers an unhandled exception or a PHP TypeError. This leads to a fatal error that terminates the execution thread of the PHP process during page rendering.\nThe attack flow proceeds as follows: 1. An unauthenticated attacker identifies the review submission endpoint provided by the WP Ultimate Review plugin. 2. The attacker crafts a request, such as a POST request, targeting the review submission functionality, replacing the expected numeric rating (e.g., '5') with a non-numeric string or a specifically crafted payload (e.g., a string or an array). 3. The plugin application logic accepts this input and persists it into the WordPress database without validation or sanitization. 4. Once the malicious review is saved, any subsequent visitor attempting to load a page that renders the affected review will encounter a fatal error. This is because the plugin executes numeric operations on the non-numeric data stored in the database, causing the PHP interpreter to cease execution.\nThe vulnerability is persistent, as the malicious entry remains in the database, consistently causing site disruption until the entry is deleted from the WordPress backend. The exposure is high, as it does not require authentication, and the attack surface is limited only by the availability of the review submission form. Because the crash occurs server-side during the processing of the page content, it provides a highly effective vector for disrupting service availability for legitimate users."
}