OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-101160

HIGH · CVSS 7.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The WP Ultimate Review plugin for WordPress versions prior to 2.4.4 is vulnerable due to inadequate validation of review ratings, allowing unauthenticated users to submit non-numeric values. This can lead to a persistent denial of service, causing fatal errors that affect all visitors until the problematic review is removed. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-101160
Severity
HIGH
CVSS
7.5
EPSS
0.34%
WordPress

Original NVD Description

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it in numeric operations when rendering reviews, allowing unauthenticated users to make the reviewed content fail with a fatal error for all visitors until the review is removed (a persistent denial of service), when user reviews are enabled.