Sceawere

Vulnerability Detail

CVE-2026-101162UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in WP Ultimate Review

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
13h ago
Vendor
Unknown
Product
WP Ultimate Review
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-03T06:16:38.893Z",
  "pubdate": "2026-10-03T06:16:38.893Z",
  "executiveSummary": "The WP Ultimate Review plugin, in versions prior to 2.4.4, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw originates from improper input sanitization and output encoding of review overview settings.\nBy injecting malicious JavaScript into review settings, an authenticated user with at least 'author' privileges can execute arbitrary code in the context of the victim's browser session.\nThe vulnerability poses a significant risk to site integrity and user security, as it allows attackers to bypass site security controls, hijack administrative sessions, or redirect users to malicious domains.\nSuccessful exploitation requires the 'author reviews' feature to be enabled and the attacker to possess an account with sufficient permissions to modify review settings.\nThe impact includes full compromise of the client-side session, potential modification of displayed content, and theft of sensitive user data, such as authentication cookies or CSRF tokens.",
  "technicalDetails": "The vulnerability exists due to a failure in the WP Ultimate Review plugin to properly sanitize or escape input data related to review overview settings before rendering the data within post content.\nIn versions 2.4.4 and below, the plugin's backend administrative interface allows for the configuration of specific review overview parameters. The application accepts these parameters without verifying their content against a whitelist or applying necessary output escaping functions such as esc_html(), esc_attr(), or esc_js().\nAn attacker with the 'author' role can leverage the 'author reviews' functionality to inject malicious scripts into these configuration fields. When these settings are saved, the malicious payload is stored persistently in the database.\nThe attack flow proceeds as follows: 1) The attacker authenticates to the WordPress dashboard with 'author' level privileges. 2) The attacker navigates to the plugin settings for review overviews. 3) The attacker submits an update containing a cross-site scripting payload (e.g., <script>alert(document.cookie)</script>) within one of the affected fields. 4) The server processes and stores this unencoded input directly into the WordPress options table. 5) When a user—such as an administrator or another visitor—views a post that utilizes the compromised review overview module, the server renders the stored payload directly into the HTML document.\nBecause the payload is not encoded, the victim's web browser interprets the string as executable JavaScript rather than literal text. This results in the execution of the payload within the security context of the victim's session.\nThe scope of this vulnerability allows for the execution of arbitrary JavaScript, enabling the attacker to perform unauthorized actions on behalf of the victim, exfiltrate sensitive session tokens via asynchronous requests, or manipulate the Document Object Model (DOM) to present phishing content or fraudulent links to the site users.\nThe core issue is a lack of server-side validation during the 'save' operation and a lack of context-aware output encoding during the rendering of the review overview template, violating standard WordPress security practices for handling user-supplied data."
}
CVE-2026-101162: Stored XSS in WP Ultimate Review (MEDIUM Severity, CVSS: 6.4) | Sceawere