OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-101161

HIGH · CVSS 7.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The WP Ultimate Review plugin for WordPress versions prior to 2.4.4 is vulnerable to a denial of service attack, allowing unauthenticated users to submit malicious review content that causes the reviewed page to crash with a fatal error on subsequent visits. This can lead to persistent downtime for affected sites, particularly if the review display settings have not been configured. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-101161
Severity
HIGH
CVSS
7.5
EPSS
0.34%
WordPress

Original NVD Description

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with a fatal error on every subsequent visit, resulting in a persistent denial of service when the WP Ultimate Review WordPress plugin before 2.4.4's review display settings have never been saved.