๐Ÿ” CVE Alert

CVE-2026-101162

UNKNOWN 0.0

WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks, when author reviews are enabled.

Vendor unknown
Product wp ultimate review
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp ultimate review

Be the first to know when new unknown vulnerabilities affecting unknown wp ultimate review are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WP Ultimate Review
0 < 2.4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b7a66222-4e30-4d70-9e2f-b91d421d285f/

Credits

Alban Roche WPScan