CVE-2026-82925
Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such installs. The Site Reviews WordPress plugin before 8.3.0's own code contains no chain onward from the injected object, so how far it reaches depends on the other code present on the site.
| Vendor | unknown |
| Product | site reviews |
| Published | Sep 10, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown site reviews
Be the first to know when new high vulnerabilities affecting unknown site reviews are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Site Reviews
7.2.2 < 8.3.0
References
Credits
Jakub Herman WPScan