CVE-2026-93778
Received Received - Intake

Stored Cross-Site Scripting in WP Yelp Review Slider Plugin

Vulnerability report for CVE-2026-93778, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Wordfence

Description

The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The malicious payload originates from an anonymous Yelp reviewer on a public platform and requires no WordPress account; it is introduced into the database during the site administrator's ordinary use of the plugin's Download Reviews feature, making the effective attacker unauthenticated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpyelp_review_slider wpyelp_review_slider to 9.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP Yelp Review Slider plugin for WordPress has a stored Cross-Site Scripting (XSS) vulnerability. This flaw allows unauthenticated attackers to inject malicious scripts into web pages via Yelp review text. The issue arises from insufficient input sanitization and output escaping in versions up to 9.2. The payload is introduced when a site administrator uses the plugin's Download Reviews feature, pulling reviews from a public Yelp platform.

Detection Guidance

Check for the presence of the WP Yelp Review Slider plugin in your WordPress installation. Look for unusual or unexpected scripts in Yelp review text imported via the plugin's Download Reviews feature. Review database entries for any injected web scripts in pages generated by the plugin.

Impact Analysis

This vulnerability can allow attackers to execute arbitrary web scripts on your WordPress site. Visitors to infected pages may have their sessions hijacked, credentials stolen, or be redirected to malicious sites. Since the attack originates from a public Yelp review and requires no WordPress account, it poses a significant risk to site visitors and administrators.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to user data or exposure of sensitive information. GDPR requires protecting user data from breaches, while HIPAA mandates safeguarding protected health information. A successful XSS attack may violate these regulations, leading to legal penalties and reputational damage.

Mitigation Strategies

Immediately update the WP Yelp Review Slider plugin to the latest version if available. If no update is available, consider disabling or removing the plugin until a patch is released. Review and sanitize all imported Yelp review data for malicious scripts before publishing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93778. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart