CVE-2026-101162
WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.
| Vendor | unknown |
| Product | wp ultimate review |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp ultimate review
Be the first to know when new unknown vulnerabilities affecting unknown wp ultimate review are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Ultimate Review
0 < 2.4.4
References
Credits
Alban Roche WPScan