Sceawere

Vulnerability Detail

CVE-2026-103519UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Ultimate Review Shortcode Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
roxnor
Product
WP Ultimate Review
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The bypass relies on WordPress's own strip_shortcodes() function unwrapping the [[tag]] double-bracket escape to a bare [tag] that survives wp_insert_post storage and fires when the publicly queryable xs_review post type is rendered through the_content.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-03T07:16:47.050Z",
  "pubdate": "2026-10-03T07:16:47.050Z",
  "executiveSummary": "The WP Ultimate Review plugin for WordPress is susceptible to an arbitrary shortcode execution vulnerability across all versions up to and including 2.4.3.\nThis flaw originates from improper input validation within the plugin's action processing logic, allowing authenticated users with subscriber-level permissions or higher to execute arbitrary shortcodes.\nThe vulnerability leverages the WordPress `strip_shortcodes()` function to bypass sanitization mechanisms by exploiting the double-bracket escape sequence `[[tag]]`.\nSuccessful exploitation permits unauthorized execution of shortcodes when the affected `xs_review` custom post type is rendered via `the_content` filter.\nThe risk implication is significant as it allows attackers to trigger sensitive shortcode functionality, potentially leading to unauthorized data disclosure, administrative actions, or privilege escalation depending on the shortcodes available within the WordPress environment.\nExploitation requires a subscriber account, making it accessible to any registered user on a vulnerable installation.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient validation of user-supplied data before passing it to the `do_shortcode` function. The plugin fails to adequately sanitize or verify the context of input data during an action processing routine, which is subsequently stored in the WordPress database.\nThe primary exploitation vector involves a bypass mechanism inherent to how WordPress handles shortcode tags. By using the double-bracket escape syntax `[[tag]]`, an attacker can inject malicious code strings that appear benign to initial sanitization or stripping functions. Specifically, when the WordPress `strip_shortcodes()` function encounters an escaped `[[tag]]` sequence, it unwraps it into a functional `[tag]` representation.\nThis resulting bare tag is then persisted into the database via `wp_insert_post`. Once the post is saved, the vulnerability is triggered when the `xs_review` post type—a publicly queryable custom post type—is rendered through the `the_content` filter. When the WordPress engine processes the content, it identifies the injected shortcode and executes it with the privileges of the system, effectively bypassing the security controls that would otherwise block direct execution of such content from lower-privileged users.\nThe attack flow proceeds as follows: 1) An authenticated attacker with subscriber-level access crafts a malicious payload containing an escaped shortcode (e.g., `[[injected_shortcode]]`). 2) The attacker submits this payload through the plugin's vulnerable action, which fails to neutralize the input. 3) The `wp_insert_post` function stores the payload in the database. 4) The plugin's logic permits the payload to be interpreted as a valid shortcode. 5) A visitor or the attacker accesses the `xs_review` post, causing `the_content` to render, which invokes `do_shortcode` and executes the injected tag.\nThis vulnerability is present in versions up to and including 2.4.3. The impact is broad, as the ability to trigger arbitrary shortcodes allows attackers to interact with other plugins or core features that utilize shortcodes for functional output, essentially granting the attacker the ability to perform operations they are not explicitly authorized to execute."
}
CVE-2026-103519: WP Ultimate Review Shortcode Injection (MEDIUM Severity, CVSS: 5.4) | Sceawere