OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-101159

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The WP Ultimate Review plugin for WordPress versions prior to 2.4.4 is vulnerable due to inadequate sanitization and escaping of user-submitted reviews, which can be exploited by unauthenticated visitors to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability poses a significant risk as it can affect any user, including administrators, who views the compromised review, potentially leading to session hijacking or site defacement. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-101159
Severity
HIGH
CVSS
7.5
EPSS
0.25%
WordPress

Original NVD Description

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.