CVE-2026-92412 PUBLISHED

Five Star Restaurant Reviews < 2.3.14 - Reflected XSS

Assigner: WPScan
Reserved: 16.09.2026 Published: 01.10.2026 Updated: 01.10.2026

The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.

Product Status

Vendor Unknown
Product Five Star Restaurant Reviews
Versions Default: unaffected
  • affected from 0 to 2.3.14 (excl.)

Credits

  • V1T finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE