CVE-2026-101160
Received Received - Intake

WP Ultimate Review Plugin Rating Validation Flaw

Vulnerability report for CVE-2026-101160, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: WPScan

Description

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_ultimate_review plugin to 2.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP Ultimate Review WordPress plugin before version 2.4.4 has a flaw where it does not check if a submitted review rating is numeric. This allows unauthenticated users to submit non-numeric ratings, which the plugin stores and later uses in calculations. When the plugin tries to process these ratings, it causes a fatal error, making the reviewed content inaccessible to all visitors until the malicious review is removed.

Detection Guidance

Check the installed version of the WP Ultimate Review plugin. If it is below 2.4.4, the system is vulnerable. You can verify this via WordPress admin panel or by inspecting plugin files for version details.

Impact Analysis

This vulnerability can cause your WordPress site to crash or become inaccessible to visitors if someone submits a non-numeric review rating. The site will remain down until the problematic review is manually deleted, resulting in a persistent denial of service for all users.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a technical denial of service issue. However, persistent unavailability of content due to this flaw could impact data accessibility requirements under these regulations if critical information becomes inaccessible.

Mitigation Strategies

Update the WP Ultimate Review plugin to version 2.4.4 or later immediately. Disable user reviews temporarily if an update is not immediately possible, as the vulnerability requires user reviews to be enabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101160. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart