CVE-2026-101159
Received Received - Intake

Stored XSS in WP Ultimate Review WordPress Plugin

Vulnerability report for CVE-2026-101159, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: WPScan

Description

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_ultimate_review plugin to 2.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the WP Ultimate Review WordPress plugin before version 2.4.4. It allows unauthenticated attackers to inject malicious scripts into reviews submitted through the plugin's public form. These scripts are stored on the server and executed when other users, including administrators, view pages displaying the reviews.

Detection Guidance

Check if the WP Ultimate Review plugin is installed and verify its version. If it is below 2.4.4, the system is vulnerable. Use WordPress admin panel or run: wp plugin list | grep ultimate-review in the WordPress directory.

Impact Analysis

An attacker could steal sensitive user data like session cookies, login credentials, or personal information by tricking users into viewing a page with a malicious review. Administrators could have their accounts compromised, leading to full site takeover. Malicious scripts could also deface the website or redirect users to phishing pages.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for protecting personal and health data. Organizations may face fines, legal penalties, and reputational damage due to non-compliance with data protection regulations.

Mitigation Strategies

Update the WP Ultimate Review plugin to version 2.4.4 or later immediately. If updating is not possible, disable the plugin or disable user reviews in the plugin settings until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101159. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart