Sceawere

Vulnerability Detail

CVE-2026-101161UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Ultimate Review Unauthenticated DoS

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
13h ago
Vendor
Unknown
Product
WP Ultimate Review
Attack Type
CWE-400 Uncontrolled Resource Consumption
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review display settings have never been saved.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-03T06:16:38.590Z",
  "pubdate": "2026-10-03T06:16:38.590Z",
  "executiveSummary": "The WP Ultimate Review WordPress plugin, in versions prior to 2.4.4, contains a critical vulnerability that allows unauthenticated remote attackers to trigger a persistent Denial of Service (DoS) condition.\nThe vulnerability arises from insufficient input validation and insecure state handling when review display settings remain in their default, unsaved configuration.\nBy submitting crafted review content, an attacker can induce a fatal error during the rendering process of the reviewed page. This error persists across all subsequent visits, effectively disabling the affected page for all users.\nBecause the exploit does not require authentication or elevated privileges, the barrier to entry is extremely low, posing a significant risk to site availability.\nSuccessful exploitation permanently disrupts service on affected pages until the administrative settings are manually updated or the malicious data is purged from the database.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper handling of review content rendering within the WP Ultimate Review plugin. Specifically, the plugin logic assumes that certain configuration parameters—which are established only after a user explicitly saves the plugin's 'Review Display Settings' in the WordPress admin panel—are initialized and available.\nWhen the plugin is in its default state (i.e., settings have never been saved), the code fails to validate or sanitize the review content input appropriately, and it lacks defensive checks for the absence of expected configuration objects. When an unauthenticated attacker submits a crafted payload via the review submission interface, this malicious content is persisted to the database.\nUpon subsequent page loads, the plugin attempts to process the crafted review content for display. Because the plugin relies on uninitialized or null display settings, the execution flow encounters a critical logic error. This error manifests as a PHP fatal error, which terminates the execution of the page script entirely, preventing the page from rendering correctly for any user.\nThe attack flow is as follows: 1) An attacker identifies a target page utilizing the WP Ultimate Review plugin. 2) The attacker submits a review containing specifically crafted data via the public-facing submission form. 3) The application stores this data in the database without sufficient validation. 4) The next time the page is accessed, the plugin's rendering engine attempts to process the stored payload using unconfigured display settings. 5) A fatal exception is triggered due to the lack of error handling in the plugin's rendering logic. 6) Every subsequent visit to the page triggers the same fatal error, resulting in a permanent DoS.\nBecause the payload is stored directly in the database and executed server-side upon rendering, the DoS is persistent. The vulnerability affects all versions of WP Ultimate Review prior to 2.4.4. The lack of authentication requirements allows any remote actor to exploit the vulnerability over the network, making this an ideal vector for disrupting site functionality."
}
CVE-2026-101161: WP Ultimate Review Unauthenticated DoS (HIGH Severity, CVSS: 7.5) | Sceawere