Sceawere
Vulnerability Detail
CVE-2026-101162UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in WP Ultimate Review
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- WP Ultimate Review
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-03T06:16:38.893Z",
"pubdate": "2026-10-03T06:16:38.893Z",
"executiveSummary": "The WP Ultimate Review plugin, in versions prior to 2.4.4, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw originates from improper input sanitization and output encoding of review overview settings.\nBy injecting malicious JavaScript into review settings, an authenticated user with at least 'author' privileges can execute arbitrary code in the context of the victim's browser session.\nThe vulnerability poses a significant risk to site integrity and user security, as it allows attackers to bypass site security controls, hijack administrative sessions, or redirect users to malicious domains.\nSuccessful exploitation requires the 'author reviews' feature to be enabled and the attacker to possess an account with sufficient permissions to modify review settings.\nThe impact includes full compromise of the client-side session, potential modification of displayed content, and theft of sensitive user data, such as authentication cookies or CSRF tokens.",
"technicalDetails": "The vulnerability exists due to a failure in the WP Ultimate Review plugin to properly sanitize or escape input data related to review overview settings before rendering the data within post content.\nIn versions 2.4.4 and below, the plugin's backend administrative interface allows for the configuration of specific review overview parameters. The application accepts these parameters without verifying their content against a whitelist or applying necessary output escaping functions such as esc_html(), esc_attr(), or esc_js().\nAn attacker with the 'author' role can leverage the 'author reviews' functionality to inject malicious scripts into these configuration fields. When these settings are saved, the malicious payload is stored persistently in the database.\nThe attack flow proceeds as follows: 1) The attacker authenticates to the WordPress dashboard with 'author' level privileges. 2) The attacker navigates to the plugin settings for review overviews. 3) The attacker submits an update containing a cross-site scripting payload (e.g., <script>alert(document.cookie)</script>) within one of the affected fields. 4) The server processes and stores this unencoded input directly into the WordPress options table. 5) When a user—such as an administrator or another visitor—views a post that utilizes the compromised review overview module, the server renders the stored payload directly into the HTML document.\nBecause the payload is not encoded, the victim's web browser interprets the string as executable JavaScript rather than literal text. This results in the execution of the payload within the security context of the victim's session.\nThe scope of this vulnerability allows for the execution of arbitrary JavaScript, enabling the attacker to perform unauthorized actions on behalf of the victim, exfiltrate sensitive session tokens via asynchronous requests, or manipulate the Document Object Model (DOM) to present phishing content or fraudulent links to the site users.\nThe core issue is a lack of server-side validation during the 'save' operation and a lack of context-aware output encoding during the rendering of the review overview template, violating standard WordPress security practices for handling user-supplied data."
}