CyberRota Analysis
AI-GeneratedThe WP Ultimate Review plugin for WordPress versions prior to 2.4.4 is vulnerable due to inadequate sanitization and escaping of user-submitted reviews, which can be exploited by unauthenticated visitors to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability poses a significant risk as it can affect any user, including administrators, who views the compromised review, potentially leading to session hijacking or site defacement. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to unauthenticated visitors, allowing them to perform Stored Cross-Site Scripting attacks against any user, including administrators, viewing a page displaying the review, when user reviews are enabled.