CVE-2026-101162 PUBLISHED

WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings

Assigner: WPScan
Reserved: 28.09.2026 Published: 03.10.2026 Updated: 03.10.2026

The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.

Product Status

Vendor Unknown
Product WP Ultimate Review
Versions Default: unaffected
  • affected from 0 to 2.4.4 (excl.)

Credits

  • Alban Roche finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE